NF / Legal / Shopify
NarrowForge Commission Ledger — Security
1. Scope
This policy describes the current security boundary for NarrowForge Commission Ledger, an embedded Shopify app that calculates and records commissions. It is an engineering description, not a penetration test or certification.
2. Shopify access
The documented workflow uses these permissions:
read_ordersandread_all_orders— import and reconcile current and historical orders and refunds.read_products— evaluate product identifiers and tags used by configured rule filters.
Customer and company identifiers are used for attribution; the app does not request profile fields, theme access, checkout access or write permissions. The all-orders grant is used for historical commission reconciliation only.
3. Authentication and tenant isolation
Shopify OAuth and authenticated Admin requests establish the store context. Server-side loaders, jobs, calculations and exports scope records to the authenticated store; a browser parameter is never treated as an authorisation boundary. Sessions, tokens and database credentials remain server-side.
4. Calculation and write safety
Money is calculated with deterministic integer units and basis points. Rule versions, attribution sources, period states and adjustments are retained as audit evidence. Locked periods are immutable, and later refunds become signed adjustments rather than silent rewrites.
5. Webhooks and disclosure
Shopify webhook authenticity is verified before processing. API errors, rate limits, missing permissions and incomplete imports remain visible as failed or partial states. Report a suspected security issue through the security support form or email support@narrowforge.com. Do not include credentials, tokens or unnecessary order data, and do not disclose the issue publicly before it has been reviewed.
Commission Ledger does not currently claim SOC 2, ISO 27001 or another formal security certification. Last updated: 2026-09-13.