Trust & security

Security at StorePilot

Last updated: July 27, 2026 · Questions: security@storepilothq.com

StorePilot connects to the systems that run your business, so security isn't a feature — it's the product. We designed it around two principles: read only what we need, and never change anything or spend money without your explicit approval.

The money-gate

Every action that spends money or edits a live listing — a reprice, a refund, an ad-budget change — is paused before it executes and requires your explicit approval. The default autonomous spend limit is $0; you opt in to any automation, per rule, on your terms. Refund auto-approval, where you enable it, applies only below a threshold you set and only once the returned item is confirmed back. Every decision is written to an immutable audit log.

Data protection

Access & authorization

Operational security

Sub-processors

We use a small set of vetted sub-processors under data-processing agreements. Current list:

ProviderPurpose
Anthropic (Claude)The reasoning model behind the agent
Cloud hosting providerApplication hosting & encrypted data storage
Encrypted secrets managerEncrypted OAuth token vault

Responsible disclosure

Found a vulnerability? We want to hear from you. Email security@storepilothq.com with details and we'll respond promptly. Please give us reasonable time to remediate before public disclosure.

A Data Processing Agreement (DPA) is available to customers on request. Enterprise customers can request our security documentation during onboarding.