GreyNod Labs logo

Cybersecurity service

Shopify Security and Configuration Review

A review of how your Shopify store is configured and customised, to identify security and configuration weaknesses you control.

A Shopify store is hosted and secured by the platform, but each merchant controls its own settings, staff access, installed apps, theme code and integrations. This review looks at the parts you control.

Who it is for

  • Shopify store owners
  • Businesses with a customised theme or several installed apps

What is in scope

  • Store settings, staff accounts and permissions
  • Installed apps and the access they have
  • Theme and custom code, where included in the agreed scope
  • Third-party scripts and integrations in scope

How we work

  1. Agree scope. We confirm what will be reviewed and obtain the access and written authorisation needed.
  2. Review and test. We review the configuration and test the customisations in scope.
  3. Report. We deliver verified findings and remediation recommendations.

What you receive

  • A written report with verified findings
  • Configuration and remediation recommendations

Limitations

  • Shopify’s own platform and infrastructure are out of scope; only merchant-controlled configuration and customisations are reviewed.
  • A security assessment reduces risk but cannot guarantee that every vulnerability will be found or that a system will remain secure.
  • Retesting is optional and can be agreed separately; it is not automatically included.

What we need from you

  • Written authorisation from the store owner
  • The access agreed for the review, for example a staff account with suitable permissions

Frequently asked questions

Do you test Shopify itself?

No. We review the configuration and customisations that you control as the merchant.

Ready to talk about your project?

Tell us what you need and we will reply with next steps.

Request a Consultation