Shopigent

Security & Trust

Giving an AI agent access to your store is a trust decision. Here is exactly how Shopigent limits, records, and controls that access.

The access model

  1. You choose the categories. Each of the 8 tool categories (Products, Orders, …) has an on/off toggle. Disabled categories are invisible to agents — the tools aren't listed, let alone callable.
  2. Reads and writes are separated by plan. Free is read-only by design; write tools only exist on paid plans.
  3. Destructive actions stop at the confirmation gate. Create, edit, delete, refund — the call pauses and a confirmation card appears in your dashboard. Nothing executes until a human approves it.
  4. Everything is written to the audit log. Tool name, full input, result, latency, timestamp. The log is append-only.

API keys

Data handling

Shopify-side protections

Reporting a vulnerability

Found something? Email shopigent@greeknous.com. We respond fast and appreciate responsible disclosure.