Starship
starship / search / agiliron

Audit report

Agiliron

Broad accessReach : broadSensitive Access

by Agiliron · Productivity · Shopify App Store

Productivity
Risk level
Broad access
Executive summary

Sell More in More Places. But Manage in One.

Key insights

  • Multi-channel order/inventory/CRM SaaS by Agiliron, US-hosted.
  • 5.0/5 rating on only 5 reviews (low sample size; not statistically robust).
  • No 'Built for Shopify' badge.
  • Privacy policy explicitly states US hosting; mentions PCI-related third-party credit card processor and ad networks.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Sell More in More Places. But Manage in One.

Key insights
  • Multi-channel order/inventory/CRM SaaS by Agiliron, US-hosted.
  • 5.0/5 rating on only 5 reviews (low sample size; not statistically robust).
  • No 'Built for Shopify' badge.
  • Privacy policy explicitly states US hosting; mentions PCI-related third-party credit card processor and ad networks.
  • No public evidence of breaches, CVEs, or AI/LLM data sharing.
  • Publisher web server is Apache; no HSTS or CSP headers detected.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Likely required for multi-channel order sync (declared functionality).

write_orders
High

Likely required to push orders captured in other channels back into Shopify.

read_products
Medium

Inventory sync requires catalog access.

write_products
High

Inventory management implies product/stock updates.

read_customers
High

CRM functionality implies customer profile access.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
agiliron.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS works (Apache) but neither HSTS nor CSP headers are set on the root response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Pass

Privacy policy references PCI compliance via a third-party credit card processor; no SOC2/ISO27001/GDPR/CCPA statements found. US hosting disclosed.

Privacy policy
Track record

Publisher reputation

Publisher
Agiliron
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.