Security overview
Obsidian Guard is designed to protect risky operational actions. Security is applied across identity, server-side authorization, integration boundaries, data handling, delivery systems, and activity evidence.
Security
A factual overview of how Obsidian Guard handles identity, authorization, credentials, operational evidence, and security reports during private beta.
Obsidian Guard is designed to protect risky operational actions. Security is applied across identity, server-side authorization, integration boundaries, data handling, delivery systems, and activity evidence.
The product is designed to collect and store the account, Shopify, workflow, decision, outcome, notification, entitlement, and operational data needed to provide enabled controls and support. Shopify field availability is limited by granted scopes and platform behavior.
Production traffic is served over HTTPS. Production configuration requires Shopify access tokens and supported adapter secrets to use an AES-256-GCM application envelope before database storage. Managed infrastructure also supplies storage-level protections; exact provider controls remain subject to provider configuration and contract.
Sensitive operations use server-side identity and authorization checks. Organization IDs scope data access, database row-level policies reinforce tenant boundaries, and plan entitlements are checked before protected capabilities are enabled. Shopify permissions remain a separate and necessary control.
Integration credentials and signing secrets remain server-side. API keys are stored as one-way hashes, the raw value is shown only when created, and keys can be revoked. Product and notification surfaces are designed not to expose stored tokens or secrets.
The service records protected-request history, reviewer decisions, execution outcomes, detected events, delivery attempts, failures, and manual-follow-up states. Operational monitoring records sanitized failure context; sensitive field names and bearer-like values are filtered before observability capture.
Obsidian Guard maintains a security incident response process for triage, containment, investigation, remediation, and customer communication appropriate to the event. Private-beta participants receive coordination through their registered contact path.
Shopify uninstall handling disconnects the integration and triggers product lifecycle records. Account deletion, retention, and customer-request handling depend on the data category and contractual or legal obligations. The precise retention schedule and deletion language remain subject to formal legal review before public launch.
Obsidian Guard does not currently publish claims of SOC 2, ISO 27001, PCI DSS, HIPAA, penetration-test coverage, a 24/7 security operations center, or a specific uptime/security SLA. Private-beta controls and provider configuration continue to be validated.
Email [email protected]. Include a clear description and safe reproduction detail. Do not access, alter, retain, or disclose customer data, and do not send credentials in email.
See the Privacy Policy for data categories and service providers. A formal subprocessor list will be published after provider and legal review rather than inferred from development configuration.