KelmoraKelmora.
ProductHow it worksPricingSecurity
Install Kelmora

Security

Last updated: 2026-09-08

How Kelmora protects your store

Kelmora is designed as multi-tenant business software. We treat tenant isolation and access control as foundational requirements, not afterthoughts.

Access and permissions

Kelmora uses the minimum Shopify scopes required — read access to orders, products, inventory, and locations. We do not request write permissions. Shopify access tokens are used only server-side and are never exposed to the browser.

Tenant isolation

Every merchant-specific query is scoped to the authenticated Shopify store derived from the trusted server session. A client-supplied shop identifier is never used as authorization.

Secrets

Shopify access tokens and our AI provider key are stored server-side only, excluded from version control, and never logged or shipped to the frontend.

Webhooks

Incoming Shopify webhooks are authenticated and verified using Shopify's official HMAC validation before any processing occurs.

AI safety

AI is an enrichment layer. The model receives only structured, de-identified business facts, and its output is validated server-side before use. The model has no direct access to Shopify APIs and cannot take actions on your store.

Reporting a vulnerability

If you believe you have found a security issue, please report it through the contact details on your Shopify app listing. We do not currently hold third-party security certifications; this page describes our engineering practices, not a certification.

KelmoraKelmora.
PrivacyTermsSecurityInstall
Always-on commerce intelligence.