Security & Compliance
Appsalon builds and manages business-critical commerce solutions on Shopify. Security and compliance are integral to how we organize ourselves, choose technology, develop, and manage solutions – from internal access controls and development processes to architecture, integrations, and technology partners.
This page describes Appsalon's overarching security principles and how we work with information security, privacy, and compliance within our own organization and in the solutions we deliver.
Security by design
Security is an integral part of the architecture from the start of a project.
When Appsalon designs and develops a solution, we consider systems, data flow, access, and integrations as part of the technical architecture.
Among other things, we work according to principles for:
- limited access to systems and data
- data minimization
- secure handling of API keys, tokens, and credentials
- personal user accounts instead of shared accounts
- protection of administrative access
- separation between systems and environments where relevant
- limited rights for integrations and APIs
- code and change control before production
These principles apply both when developing new solutions and when existing e-commerce architecture is being further developed.
Internal security at Appsalon
The security of the solutions we deliver is connected to how Appsalon itself operates.
All Appsalon employees are located in Norway and work within the same internal security routines. Access to customer systems and internal services is granted on a need-to-know basis and adjusted or removed when roles, responsibilities, or work requirements change.
Google is used as a central part of our identity and access management, providing a common starting point for authentication and access across services. Relevant Google services are covered by documented security and compliance programs, including ISO/IEC 27001 as well as SOC 2 and SOC 3.
Appsalon uses a standardized Apple-based work environment. Standardization enables the establishment of common requirements for encryption, security updates, software, administrative rights, and configuration across the organization.
Apple builds security features into both hardware and operating system, including hardware root of trust, secure boot, encryption, and Secure Enclave for the protection of cryptographic keys and sensitive information.
At the office, Appsalon uses a controlled corporate network as part of the overall security setup.
Our internal routines include periodic access reviews, central identity management, multi-factor authentication for critical services where supported, secure handling and rotation of credentials, security reviews of source code, control of dependencies and known vulnerabilities, automated testing, logging and traceability, security checks of workstations, continuous security updates, and routines for handling security incidents.
Security routines evolve in line with technology, solutions, and the risk landscape.
Secure development and management
Security work is incorporated throughout the entire development and management process.
Appsalon uses version control and code review, automated testing, dependency control, secure handling of secrets and credentials, and controlled development and deployment processes.
Credentials are not stored openly in the source code. Keys and tokens are rotated or revoked when access, risk, or need dictates.
Automated testing is used for critical functionality before changes are published. Logging and traceability are used where relevant for operations, troubleshooting, and security.
Security checks are included both when developing new solutions and in the ongoing management of solutions for which Appsalon is responsible.
Technology platforms and partners
Shopify is at the core of most solutions Appsalon delivers.
The Shopify platform is PCI DSS Level 1-compliant, and Shopify has SOC 2 Type II and SOC 3 reports for the services they provide.
By using Shopify's checkout and payment infrastructure, sensitive payment information can be handled within Shopify's established security framework rather than in customer-specific application code.
Appsalon also builds on other established technology platforms and services with documented security controls, audits, and certifications.
The same requirements form the basis when we select technology partners and solutions within the Shopify ecosystem. Security work, compliance, data processing, access model, and the vendor's role in the overall architecture are part of the assessment.
The requirements customers place on Appsalon should also be reflected in the requirements we place on the technology and partners included in the delivery.
Certifications and audit reports apply to the individual vendor and the services covered by their defined scope. They do not imply that Appsalon or a customer solution automatically inherits the same certification.
Appsalon is responsible for the architecture, integrations, configuration, and functionality that we ourselves develop and manage.
Data, privacy, and GDPR
Privacy is included as part of the technical architecture.
Appsalon uses data minimization and control over data flow as practical principles when developing solutions and integrations. Data access and rights are limited to what is necessary for the function provided.
This applies to both customer-specific functionality and integrations with ERP, PIM, CRM, logistics, finance, and other systems.
As part of our technical privacy work, we assess where data is processed, which systems have access, and how information is moved between systems.
The customer retains responsibility for their own processing basis and other organizational and legal obligations related to privacy.
AI and regulatory requirements
Appsalon has internal guidelines for the use of AI.
Sensitive credentials, API keys, and unnecessary personal data should not be shared with AI services. AI is assessed according to the same principles as other external services, with control over access, data minimization, and what information is processed.
When AI is included in a customer solution, this is considered as part of the overall architecture, data processing, and security model.
Appsalon follows developments in European AI regulation, including the EU AI Act and the implementation of the regulations in Norway. As of August 2026, the government is still working on Norwegian implementation and has announced a new public hearing for the AI Act.
Incident handling
Appsalon has routines for handling and following up on security incidents.
In the event of suspected incident, priority is given to limiting potential damage, controlling affected access and credentials, reviewing relevant logs, and identifying affected systems.
Affected customers are involved where relevant. Incidents are documented and followed up with necessary technical or organizational measures.
Lessons learned from incidents are used to improve existing controls and routines.
Compliance and division of responsibility
Security and compliance in an e-commerce solution are distributed among several parties.
Platform providers are responsible for the security and controls in the services they deliver.
Appsalon is responsible for architecture, development, integrations, configuration, and the technology we ourselves deliver and manage.
The customer is responsible for their own users, organizational routines, processing basis, and the company's other legal and regulatory obligations.
Standards and frameworks such as ISO 27001, SOC 2, and PCI DSS document defined parts of the security work at the respective providers. They do not replace the assessment of security in the overall solution.
Security requirements in customer projects
Larger businesses often have their own requirements for information security, privacy, vendor management, data handling, and technical architecture.
Appsalon collaborates with the customer's IT, security, privacy, and compliance teams when this is part of the project.
We can document and review, among other things, solution architecture, integrations and data flow, technical access, relevant technology platforms and subcontractors, security controls, and development and management processes.
Security and compliance requirements are clarified as early as possible in the project and are included as part of the technical architecture and delivery.
Last updated: August 2026

