Starship
starship / search / shippit-connect

Audit report

Shippit

Broad accessReach : broadSensitive Access

by Shippit · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Faster, cheaper & smarter order delivery for Shopify

Key insights

  • SOC 2 Type 2 attested per publisher website
  • Active responsible security disclosure program (security@shippit.com) and historical Bugcrowd VDP
  • Australian publisher (Sydney) with operations spanning APAC + US
  • HSTS enabled on primary domain; valid Cloudflare-fronted TLS

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Faster, cheaper & smarter order delivery for Shopify

Key insights
  • SOC 2 Type 2 attested per publisher website
  • Active responsible security disclosure program (security@shippit.com) and historical Bugcrowd VDP
  • Australian publisher (Sydney) with operations spanning APAC + US
  • HSTS enabled on primary domain; valid Cloudflare-fronted TLS
  • No specific CVEs or confirmed breaches found for Shippit
  • No declared LLM/AI usage in privacy policy
  • Cloudflare + AWS infrastructure (sub-processor disclosure)

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to fetch orders for shipping label creation

write_orders
High

Likely required to update fulfillment status and tracking

read_fulfillments
Medium

Required for shipment management

write_fulfillments
High

Required to create/update fulfillments

read_customers
High

Required to obtain shipping addresses (PII)

read_products
Medium

Required for parcel dimensions/weights

read_locations
Low

Required for multi-location dispatch

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shippit.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS max-age=31536000 enabled; CSP only sets frame-ancestors (no full directive set). Cloudflare-fronted.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Fail
PCI DSS Fail

SOC 2 Type 2 attested. GDPR + Australian Privacy Principles referenced. ISO27001/PCI not confirmed.

Privacy policy
Track record

Publisher reputation

Publisher
Shippit
Verified Shopify Partner
No
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.