Trust
Security
Last updated July 2026
Our Approach
Security isn't a checkbox for us — PhilDesk sits inside your support inbox and your Shopify store, so we design every part of the system assuming it has to earn that trust. This page describes the practices we follow today; we'll keep it updated as the program matures.
Encryption in Transit
All traffic to and from PhilDesk — the dashboard, the API, and the live chat widget — is encrypted with TLS. We don't accept unencrypted connections to any production endpoint.
Encryption at Rest
Sensitive credentials — including the IMAP/SMTP mailbox credentials you connect for email automation — are encrypted at rest using AES before they're stored. Application secrets and API keys are kept out of source control and managed as environment-level secrets, not in the database.
OAuth-Scoped Shopify Access
PhilDesk connects to your store through Shopify's OAuth flow and only ever requests the specific scopes it needs — reading orders, products and policies, and acting on support requests you've configured, like issuing a refund within the limits you set. You can review or revoke access from your Shopify admin at any time.
Data Hosting & Residency
Our production infrastructure is hosted with EU-based providers. We don't route customer support content through servers or sub-processors that aren't bound by our data processing terms. (Exact regions and sub-processors are documented in our Data Processing Agreement, available on request.)
Compliance & Audits
We follow SOC 2-aligned practices in how we build and operate PhilDesk — access controls, encrypted secrets, audit logging on sensitive actions — and SOC 2 readiness is actively in progress. We don't hold a SOC 2 certification today, and we won't claim one until it's actually issued.
Responsible Disclosure
Found a security issue? We want to know before anyone else does. Email [email protected] with details and, if possible, steps to reproduce. We'll acknowledge reports promptly, keep you updated as we investigate, and won't pursue legal action against good-faith researchers who report responsibly and avoid data destruction, privacy violations, or service disruption.
Operational Status
We don't yet run a public status page with historical uptime — that's on our roadmap. For real-time incident updates or to check on a specific outage, contact [email protected] or [email protected] and we'll get back to you directly.