Starship
starship / search / shipstation-shipping

Audit report

ShipStation

Broad accessReach : broadSensitive Access

by ShipStation (Auctane) · Shipping · Shopify App Store

Shippingv11.5.0
Risk level
Broad access
Executive summary

ShipStation (groupe Auctane, ex-Stamps.com / Endicia) est une plateforme shipping mature. Risque Medium, large surface order/customer pour la gestion d'envois, mitigée par SOC 2 et l'envergure du groupe.

Key insights

  • Plateforme shipping multi-carriers leader US.
  • Risque Medium, surface order/customer étendue pour gestion expédition.
  • Groupe Auctane (PE Thoma Bravo), SOC 2 Type II.
  • Note merchants 4,0, frustrations sur l'UX historiquement.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

ShipStation (groupe Auctane, ex-Stamps.com / Endicia) est une plateforme shipping mature. Risque Medium, large surface order/customer pour la gestion d'envois, mitigée par SOC 2 et l'envergure du groupe.

Key insights
  • Plateforme shipping multi-carriers leader US.
  • Risque Medium, surface order/customer étendue pour gestion expédition.
  • Groupe Auctane (PE Thoma Bravo), SOC 2 Type II.
  • Note merchants 4,0, frustrations sur l'UX historiquement.
  • Plus de 14 000 marchands sur Shopify.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Génération étiquettes.

write_orders
High

MAJ status expédition.

read_customers
High

Adresses livraison.

read_fulfillments
Medium

État fulfillment.

write_fulfillments
High

Création fulfillments.

write_shipping
High

Étiquettes.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shipstation.com
TLS grade
A+
HSTS
Enabled
CSP
Enabled

TLS 1.3, HSTS, CSP.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Fail
PCI DSS Fail

SOC 2 Type II + GDPR + CCPA. DPA publique.

Privacy policy
Track record

Publisher reputation

Publisher
ShipStation (Auctane)
Verified Shopify Partner
Yes
Years active
14
Other apps
1
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.