Shopify security audit by a human.
Shopify's platform is PCI-certified and locked down — but everything you add on top (apps, theme code, staff accounts) is on you. We audit that layer by hand and tell you exactly what to fix.
Shopify secures the platform. You're responsible for what runs on it.
Shopify is a PCI DSS Level 1 certified platform — hosting, checkout infrastructure and card data are locked down and Shopify’s responsibility, not yours. That’s genuinely strong, and it’s why we don’t test it: it’s already covered, and probing it would be against Shopify’s terms.
What Shopify’s certification does not cover is everything a merchant adds on top: installed apps (often with broad permissions to customer data and orders), custom theme code, staff account security, and any checkout customizations. That merchant-side layer is exactly where real incidents happen — and exactly what this audit tests.
| Shopify (the platform) | Your Shopify audit | |
|---|---|---|
| Payment processing & PCI | Certified, Shopify’s responsibility | Not re-tested — already covered |
| Core hosting & infrastructure | Managed and secured by Shopify | Not re-tested — already covered |
| Installed apps | Not covered by Shopify | Permissions and exposure reviewed |
| Theme code (Liquid & JS) | Not covered by Shopify | Reviewed for exposed secrets & insecure logic |
| Staff accounts & 2FA | Not covered by Shopify | Checked, hardening recommended |
| DNS & email authentication | Not covered by Shopify | SPF / DKIM / DMARC checked |
What we actually test
- Installed-app permissions — what data and functionality each app can access, and whether that scope matches what the app actually needs to do.
- Theme code — Liquid templates and storefront JavaScript checked for exposed API keys or secrets, insecure client-side logic, and injected/unvetted third-party scripts.
- Staff account security — who has access, whether 2FA is enforced, and whether permissions are scoped to what each person actually needs.
- DNS & email authentication — SPF, DKIM and DMARC, so your domain can’t be easily spoofed for phishing.
- Security headers — CSP, frame protection and cookie flags on your storefront.
- Checkout customizations — for Shopify Plus stores using checkout extensibility, reviewed for the same class of logic flaws we check on any custom checkout flow.
Every finding is verified by hand before it goes in the report. Testing only begins after you verify store/domain ownership and we record an Authorization to Test — we never touch a store we haven’t been authorized to test.
Common questions
Is Shopify already PCI compliant, so why would I need an audit?
What exactly do you test on a Shopify store?
Do you need my Shopify admin login?
Can a vulnerable app really put my store at risk?
Is this different from your WordPress audit?
What does it cost?
Keep reading
Start with the free check
Passive recon on your Shopify domain — no login, no charge, no impact on your store.