Security & privacy
Your store data deserves serious infrastructure.
sndit only asks for the Shopify permissions required for the features you use, and is built so your store context stays yours.
Architecture
How sndit is built.
A high-level view of the controls we design around. We don't publish implementation specifics that would weaken them.
- Shopify OAuth for store authorization
- Tenant-isolated application architecture
- Encrypted transport (TLS)
- Encryption at rest
- Least-privilege internal access
- Monitored infrastructure
- Auditability of marketing actions
- Secrets stored and used server-side only
Data & AI
What AI does and doesn’t see.
No cross-store AI context
Your Brand Brain is scoped to your store. It is not shared with or used to inform other merchants.
Minimized PII exposure
sndit is designed to keep customer personal data out of AI prompts wherever it isn't required for the task.
Merchant-controlled permissions
You grant the Shopify scopes you're comfortable with, and can revoke access at any time.
Current stage
Honest about where we are.
sndit is in early access. Capabilities and permissions are expanding as features ship, and we describe requested Shopify scopes at install time. If a feature isn't live yet, the site labels it that way.