Security and control

Security Policy

A clear account of the security principles, shared responsibilities and reporting route around Liva 7.

Reviewed
6 September 2026
Operator
David Cope
Contact
support@liva7.com
Applies to
Liva 7 website, Shopify app and related services

This page describes security principles, not a certification or an absolute guarantee. Specific assurance should be claimed only when current evidence supports it.

Security by boundary.

Liva 7 is designed around tenant separation, approved Shopify access, explicit action authority, protected credentials, verified webhooks, rate limits, audit records, monitoring and controlled deletion. Network connections under Liva 7's control are designed to use encrypted transport.

Access and operational control.

Operational access should follow legitimate need and least privilege. Liva 7 separates visibility, preparation, approval and execution so seeing information does not automatically grant authority to publish or act.

Important actions retain their reasoning, authority, result and available rollback context in a reviewable receipt.

Shared responsibility.

You are responsible for your Shopify account, staff permissions, credentials, installed themes and apps, lawful configuration and final publication choices. Use unique credentials, remove access that is no longer needed and report suspected compromise promptly.

Incidents and reporting.

Security signals and operational logs may be used to contain and investigate an incident. Where an incident triggers legal or Shopify notification duties, Liva 7 will follow the applicable process.

Report a concern to support@liva7.com. Include a clear description and safe reproduction steps; do not access data that is not yours or publicly disclose a live vulnerability before there is a reasonable opportunity to investigate it.