Commerce has become business-critical infrastructure
A modern online store is closely connected to the rest of the business. Product data, inventory, orders, customers, payments, logistics, and finance move between multiple systems, and both people and applications have access to various parts of the solution.
Security must therefore be evaluated across the entire architecture.
At Appsalon, security is integrated from the start of a project. We consider systems, data flow, access, and integrations as part of the architecture – not as a separate layer added afterwards.
The principles we work by include:
-
limited access to systems and data
-
data minimization
-
secure handling of API keys, tokens, and credentials
-
personal user accounts instead of shared accounts
-
protection of administrative access
-
separation between systems and environments where relevant
-
limited rights for integrations and APIs
-
control of code and changes before production
Security within Appsalon
The security in the solutions we deliver is linked to how Appsalon itself operates.
All Appsalon employees are based in Norway and work within the same internal security routines. Access to customer systems and internal services is granted as needed and adjusted or removed when roles and responsibilities change.
Google is used as a central part of our identity and access management, with a common starting point for authentication and access across services.
Google has extensive security and compliance programs and undergoes independent audits, including those related to ISO/IEC 27001, SOC 2, and SOC 3.
Appsalon uses a standardized Apple-based work environment. This allows for common requirements for encryption, security updates, software, administrative rights, and configuration across the organization.
Apple builds security mechanisms directly into hardware and operating systems, including for encryption, secure boot, and hardware-protected key management.
In the office, Appsalon uses a controlled corporate network as part of the overall security setup.
Our internal security routines include:
-
periodic review and removal of access
-
centralized identity and access management
-
multi-factor authentication where relevant
-
secure handling, rotation, and revocation of keys, tokens, and credentials
-
source code security review
-
control of dependencies and known vulnerabilities
-
automated testing
-
logging and traceability where relevant
-
periodic security checks of work devices
-
ongoing security updates
-
routines for handling and following up on security incidents
AI is covered by the same internal security requirements. Appsalon has its own guidelines for AI use, and sensitive credentials, API keys, and unnecessary personal data should not be shared with AI services. We also follow developments in European AI regulation, including the EU AI Act.
Technology choices and partners
Our technology choices are part of our security and compliance efforts.
Shopify is at the core of most solutions Appsalon delivers. The Shopify platform is PCI DSS Level 1 compliant, and Shopify has SOC 2 Type II and SOC 3 reports for the services they provide.
Shopify's checkout and payment infrastructure makes it possible to handle sensitive payment information within Shopify's established security framework rather than in customer-specific application code.
Appsalon also builds on other established technology platforms and services with documented security controls. Our technology stack includes services with SOC 2 Type II reporting and ISO 27001 certification within the respective scopes of the providers.
We apply the same requirements when choosing technology partners and systems for our own organization.
The same security and compliance requirements apply when Appsalon selects technology partners and solutions within the Shopify ecosystem. We evaluate, among other things, the vendors' security work, compliance, data processing, and documented control environments as part of the vendor and partner assessment.
This creates a consistent chain of requirements: the demands customers place on Appsalon must also be reflected in the demands we place on the technology and partners included in the delivery.
Certifications and audit reports apply to the individual vendor and the services covered by their defined scope. Appsalon is responsible for the architecture, integrations, configuration, and functionality that we develop and manage ourselves.
Integrations, data, and GDPR
Integrations are a central part of many of the solutions Appsalon builds. ERP, PIM, inventory, logistics, finance, CRM, and other systems can be closely connected to the commerce platform.
Appsalon limits data access and rights to what is necessary for each individual integration. Data minimization and control over data flow are part of our technical work with GDPR and privacy.
The solutions are built with clear control over which systems process data, what access is granted, and how information is moved between systems.
The customer retains responsibility for their own processing basis and other organizational and legal obligations related to privacy.
Secure development and ongoing management
Security work continues throughout the entire development and management process.
In working with customer solutions, Appsalon uses, among other things:
-
version control and code review
-
automated tests before production
-
control of dependencies and known vulnerabilities
-
secure handling of secrets and credentials
-
controlled development and deployment processes
-
logging and traceability where relevant
-
routines for handling security incidents
Source code and dependencies are reviewed with security as part of the development work. Credentials should not be stored openly in the source code, and keys and tokens can be rotated or revoked when access, need, or risk changes.
Automated testing is used for critical functionality before changes are published.
In the event of security incidents, Appsalon has routines for controlling affected access and credentials, reviewing relevant logs, mapping affected systems, and following up on the incident.
Security controls are included both in the development of new solutions and in the ongoing management of solutions for which Appsalon is responsible.



Share:
AI becomes part of the commerce architecture – and the demands come with it