Starship
starship / search / nosto-personalization-for-shopify

Audit report

Nosto

Broad accessReach : moderateSensitive Access

by Nosto Solutions Ltd · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Powerful Personalization. Made Easy.

Key insights

  • Established AI/personalization vendor with $19.6M ARR and ~$15.7M raised; not a fly-by-night developer.
  • 4.8 rating with 60 reviews indicates moderate Shopify app usage; flagship product is broader CXP/SaaS sold off-Shopify.
  • Publisher uses Cloudflare + WP Engine for primary site; TLS clean but HSTS/CSP not enforced.
  • Mentions Huginn AI and agentic commerce, indicating LLM/ML use, though specific providers are not disclosed publicly.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Powerful Personalization. Made Easy.

Key insights
  • Established AI/personalization vendor with $19.6M ARR and ~$15.7M raised; not a fly-by-night developer.
  • 4.8 rating with 60 reviews indicates moderate Shopify app usage; flagship product is broader CXP/SaaS sold off-Shopify.
  • Publisher uses Cloudflare + WP Engine for primary site; TLS clean but HSTS/CSP not enforced.
  • Mentions Huginn AI and agentic commerce, indicating LLM/ML use, though specific providers are not disclosed publicly.
  • Dedicated Legal Center with vulnerability disclosure process via Stackla (acquired by Nosto) help center.
  • No public records of CVEs or data breaches involving Nosto found.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required for product personalization and recommendation engine.

read_orders
High

Typical for personalization based on purchase history; exposes order PII.

read_customers
High

Typical for behavioral segmentation; exposes customer PII including email.

read_themes
Medium

Typical for installing on-site script tag / theme app extension for personalization widgets.

read_content
Low

Required to personalize content blocks and pages.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
nosto.com
TLS grade
A
HSTS
Missing
CSP
Missing

Cloudflare-fronted, WP Engine origin; valid HTTPS but missing HSTS and CSP headers on marketing site.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy program and security documents are linked from a dedicated Legal Center, but specific certifications (GDPR/CCPA/SOC2/ISO27001/PCI DSS) are not confirmable from the public landing page. EU-headquartered company implies GDPR posture in practice, but no public certificate was confirmed.

Privacy policy
Track record

Publisher reputation

Publisher
Nosto Solutions Ltd
Verified Shopify Partner
No
Years active
15
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Catalog, behavioral events, and order/customer signals fed into Nosto's personalization, recommendation, and search models (branded as 'Huginn AI'); specific LLM providers not publicly disclosed.

Retention policy

unknown