Skip to content

Security and data handling

Catalog access should be narrow, traceable, and revocable.

Catavexa is designed around product-feed data, tenant isolation, protected credentials, deterministic safety rules, and merchant-controlled connections.

Core controls

Defense in depth around connected commerce data.

Security spans the public edge, authentication flows, application queries, credential handling, background jobs, logs, and incident response.

01

Encrypted connections

Catavexa uses HTTPS for public traffic and secure service connections in production.

02

Protected credentials

Shopify and Google tokens are treated as secrets, encrypted for production storage, and redacted from logs.

03

Tenant isolation

Merchant-owned records are queried within the authenticated shop context to prevent cross-store access.

04

Verified callbacks

Shopify webhook HMAC, OAuth state, session authentication, and authorized redirect flows are validated.

05

Least privilege

Catavexa requests catalog, inventory, Markets, locale, and translation access needed for feed operations—not customer or order scopes.

06

Operational safeguards

Background work uses controlled queues, retry limits, audit events, uninstall shutdown, and sensitive-field log redaction.

Data minimization

Product feeds do not need customer or payment data.

Catavexa’s core Shopify access is limited to store and catalog operations such as products, variants, inventory, locations, Markets, locales, and translations. It does not require customer records, orders, payment cards, addresses, or customer emails.

Connected Google data

  • Merchant Center account and data-source identifiers
  • Submitted and processed product records
  • Product and account issues
  • OAuth credentials needed for the authorized connection
  • Synchronization and reconciliation state

AI guardrails

AI can suggest copy. It cannot redefine the transaction.

Catavexa separates suggestion generation from deterministic catalog facts and requires merchant review before accepted content becomes part of a feed revision.

AI may suggest

Content and guidance

Titles, descriptions, Google categories, and plain-language issue explanations.

AI may not control

Commercial truth

Price, currency, inventory, availability, GTIN, SKU, variant identity, or landing-page URL.

Merchant controls

Review and reversal

Suggestions can be accepted or rejected, retained in audit history, and rolled back when the plan supports it.

Responsible disclosure

Found something that could put merchants or data at risk?

Email security@catavexa.com with a clear description, reproduction steps, and impact. Do not access data that is not yours or disrupt live service.

Email security