Starship
starship / search / accentuate

Audit report

Accentuate Custom Fields

Broad accessReach : broadSensitive Access

by Accentuate · Productivity · Shopify App Store

Productivity
Risk level
Broad access
Executive summary

Unlimited fields for every aspect of your Shopify store

Key insights

  • Built for Shopify badge present, has passed Shopify's BFS quality bar
  • 4.8 rating across 158 reviews, mature app
  • Publisher website is hosted on Shopify infrastructure (Cloudflare/GCP europe-west1), strong HTTPS posture with HSTS and CSP
  • No CVEs, breaches, or public security incidents found for Accentuate / Accentuate Digital

Top findingsview all

  • High
    Broad write scopes across multiple Shopify resources
Synthesis

Analysis summary

Unlimited fields for every aspect of your Shopify store

Key insights
  • Built for Shopify badge present, has passed Shopify's BFS quality bar
  • 4.8 rating across 158 reviews, mature app
  • Publisher website is hosted on Shopify infrastructure (Cloudflare/GCP europe-west1), strong HTTPS posture with HSTS and CSP
  • No CVEs, breaches, or public security incidents found for Accentuate / Accentuate Digital
  • Privacy policy is thin on specifics: no named sub-processors, no certifications, no defined retention period
  • Scope surface is broad for a metafields app (write to customers/orders/online store/admin)
  • No evidence of LLM/AI usage

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Includes sensitive customer data, device and activity data per app listing

write_customers
High

Allows mutation of customer records

read_users
Medium

Staff/contributor data exposure

write_products
Medium

Core to metafield/custom-field functionality but enables product mutation

write_orders
High

Order modification capability not strictly needed for a custom-fields app

write_themes
High

Online Store edit access enables theme code modification and storefront injection

write_metaobjects
Medium

Custom data edit, primary purpose of the app

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
accentuate.io
TLS grade
A
HSTS
Enabled
CSP
Enabled

Publisher marketing site is hosted on Shopify (Cloudflare edge, GCP europe-west1 origin). Strong headers: HSTS max-age ~91 days, CSP with frame-ancestors 'none' and upgrade-insecure-requests, x-frame-options DENY, x-content-type-options nosniff. Note: these headers reflect the marketing site, not necessarily the app backend.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

No formal certifications declared in privacy policy. Policy is generic and does not commit to GDPR/CCPA-specific procedures, named sub-processors, or defined retention windows.

Privacy policy
Track record

Publisher reputation

Publisher
Accentuate
Verified Shopify Partner
Yes
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.