Security
We treat security as a core feature, not an afterthought. Here's how we protect your data and your customers'.
Encryption everywhere
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. No exceptions.
Minimal data collection
We only collect what we need to provide enrichment services. No unnecessary data is stored.
Role-based access
Internal access to customer data is strictly controlled and audited. Only authorized engineers can access production data.
Regular audits
We regularly review our systems and security controls.
Incident response
We have a documented incident response plan. In the event of a breach, we notify affected customers within 72 hours.
Shopify API security
We use the minimum required Shopify API scopes and never store Shopify access tokens beyond their necessity.
Found a vulnerability?
We appreciate the work of security researchers. If you've discovered a potential security issue, please contact us privately so we can address it before public disclosure.
We commit to acknowledging reports within 24 hours and providing a fix timeline within 7 business days for confirmed vulnerabilities.
security@sonarid.co- sonarid.co and all subdomains
- sonarID Shopify app
- sonarID REST API
- Social engineering attacks
- Physical security
- Third-party services