Skip to main content
NeatPO
Legal

Security

What is implemented, and what is not claimed.

  1. 01

    Access and identity

    Users are authenticated through Shopify. Requests are scoped to the store they came from, and every record and stored file carries the store it belongs to.

  2. 02

    Files

    Object storage is private. Downloads are authorised on the server and issued as short-lived links.

  3. 03

    Uploads

    File type is checked by content, not by extension. Type, size and page limits are enforced before parsing, and spreadsheets are checked for formula injection on export.

  4. 04

    Webhooks

    Shopify webhooks are verified by HMAC and deduplicated by webhook ID before any work is queued.

Reporting a problem

Report a suspected vulnerability through the contact page and we will respond.

support@neatpo.com

No third-party security certification has been completed. We do not display badges we have not earned.

We do not claim SOC 2, ISO 27001 or GDPR certification. No such certification has been obtained.