Security

Read-only, advisory by design

CompetitorLens operates in read-only advisory mode. It never writes to your store, never reprices, and never sends campaigns or emails on your behalf.

Least-privilege access

We request a single, minimum Shopify scope: read_products. No order data, no customer data, no write scopes. Access tokens are stored encrypted, never in plain text.

Tenant isolation

Your private store data is account-scoped. Public competitor data may be shared infrastructure (we monitor a public storefront once and reuse it), but your private data and interpretations are never visible to another account.

Evidence & source logging

Every recommendation links to the source snapshot it came from, with a captured timestamp and content hash, so claims are auditable.

Human approval gates

Any action with a side effect is gated behind explicit human approval. The system does not act autonomously on your store.

Vulnerability reporting

Report security issues to security@competitorlens.net. We review reports promptly and will acknowledge receipt.

Ongoing security

We continually improve our security practices, and formal third-party audits and certifications are part of our roadmap. If your organization has specific security or compliance requirements, contact us at the address above.