Audit report
Shippit
Broad accessReach : broadSensitive Accessby Shippit · Orders and shipping · Shopify App Store
Faster, cheaper & smarter order delivery for Shopify
Key insights
- ◆SOC 2 Type 2 attested per publisher website
- ◆Active responsible security disclosure program (security@shippit.com) and historical Bugcrowd VDP
- ◆Australian publisher (Sydney) with operations spanning APAC + US
- ◆HSTS enabled on primary domain; valid Cloudflare-fronted TLS
Top findings
Analysis summary
Faster, cheaper & smarter order delivery for Shopify
- ◆SOC 2 Type 2 attested per publisher website
- ◆Active responsible security disclosure program (security@shippit.com) and historical Bugcrowd VDP
- ◆Australian publisher (Sydney) with operations spanning APAC + US
- ◆HSTS enabled on primary domain; valid Cloudflare-fronted TLS
- ◆No specific CVEs or confirmed breaches found for Shippit
- ◆No declared LLM/AI usage in privacy policy
- ◆Cloudflare + AWS infrastructure (sub-processor disclosure)
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to fetch orders for shipping label creation |
write_orders | High | Likely required to update fulfillment status and tracking |
read_fulfillments | Medium | Required for shipment management |
write_fulfillments | High | Required to create/update fulfillments |
read_customers | High | Required to obtain shipping addresses (PII) |
read_products | Medium | Required for parcel dimensions/weights |
read_locations | Low | Required for multi-location dispatch |
read_ordersRequired to fetch orders for shipping label creation
write_ordersLikely required to update fulfillment status and tracking
read_fulfillmentsRequired for shipment management
write_fulfillmentsRequired to create/update fulfillments
read_customersRequired to obtain shipping addresses (PII)
read_productsRequired for parcel dimensions/weights
read_locationsRequired for multi-location dispatch
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shippit.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS max-age=31536000 enabled; CSP only sets frame-ancestors (no full directive set). Cloudflare-fronted.
Compliance & certifications
SOC 2 Type 2 attested. GDPR + Australian Privacy Principles referenced. ISO27001/PCI not confirmed.
Privacy policyPublisher reputation
- Publisher
- Shippit
- Verified Shopify Partner
- No
- Years active
- 9
- Other apps
- 0