TUNGA← Back to site

Trust Center

Last updated: September 15, 2026

This page describes controls that exist in the product today and clearly separates them from launch work still in progress.

Security architecture

  • Every workspace query is scoped to a server-resolved tenant identity; client-supplied workspace IDs are not trusted.
  • Shopify credentials are encrypted with AES-256-GCM. Passwords are salted and hashed; sessions are cryptographically signed.
  • Secrets, authorization headers and tokens are redacted from structured application logs.
  • Shopify connections use the official Admin API and do not inject scripts or code into the storefront theme.

Safe operations

  • Changes pass through preview, approval policy, server-enforced hard limits, execution and item-level verification.
  • Partial failures are reported as partial. Failed supported items can be retried without rerunning successful items.
  • Protected tags, excluded products, archived-product protection and maximum price movement rules cannot be bypassed by Autopilot.
  • Rollback capability is shown per field; we do not claim rollback where an operation cannot be safely reversed.

Privacy and lifecycle

Order and customer data is fetched on demand and is not persisted as a separate customer database. Account export, authenticated deletion and Shopify's required data-request/redaction/uninstall webhooks are implemented. See the Privacy Policy for details.

Reliability

Health checks, request correlation, webhook signature verification, idempotent billing events, bounded Shopify retries and stale-operation reconciliation are built in. Database backup and restore use the hosting provider's point-in-time recovery controls.

Current assurance status

TUNGA does not currently claim SOC 2 or ISO 27001 certification and has not yet completed an independent penetration test. These are roadmap items, not implied certifications. Security reports can be sent to e.sonmez@dijipilot.com.

© 2026 TUNGAPrivacy Policy · Terms of Service · Trust Center · Status · Contact