Security Policy

Last Updated: 6 January 2026

At Liva 7, security is at the core of everything we do. We understand that you trust us with your business data, and we take that responsibility seriously. This Security Policy outlines the measures we implement to protect your information, maintain the integrity of our platform, and ensure a safe experience for all merchants using EngageAI.

Data Protection Overview

We employ multiple layers of security to safeguard your data from unauthorized access, disclosure, alteration, or destruction. Our approach includes:

  • End-to-end encryption: All data transmitted between your store and EngageAI is encrypted using industry-standard TLS 1.3 protocols.
  • Secure hosting: Our infrastructure is hosted on enterprise-grade cloud platforms with SOC 2 Type II compliance and 99.9% uptime guarantees.
  • Access controls: We implement role-based access control and multi-factor authentication for all internal systems.
  • Data isolation: Each merchant's data is logically separated and encrypted at rest using AES-256 encryption.

Secure Data Transmission

All communication between your Shopify store and Liva 7 is secured using Transport Layer Security (TLS) encryption. This ensures that data in transit cannot be intercepted or tampered with by malicious actors.

We use HTTPS exclusively across all EngageAI services. Our SSL certificates are regularly updated and monitored to ensure continuous protection against man-in-the-middle attacks and data interception.

Internal Access & Least Privilege

We follow the principle of least privilege, ensuring that team members have access only to the data and systems necessary for their specific roles. Our internal security practices include:

  • Access to merchant data is granted only to authorized personnel who require it to perform their duties.
  • All access is logged, monitored, and reviewed regularly for compliance and security audits.
  • Team members undergo security training and sign confidentiality agreements.
  • Access credentials are rotated periodically and immediately revoked upon role changes or termination.

Monitoring, Logging & Incident Response

We maintain comprehensive logging and monitoring systems to detect and respond to potential security threats in real time. Our systems track access patterns, system changes, and anomalous behavior to identify and mitigate risks before they impact your data.

Our incident response team is available 24/7 to address potential security threats. In the event of a security incident, we follow a documented response protocol that includes containment, investigation, remediation, and transparent communication with affected merchants.

Third-Party Service Providers

Liva 7 partners with carefully vetted third-party service providers to deliver our platform. All partners are required to maintain security standards that meet or exceed our own. These providers include:

  • Cloud infrastructure providers with SOC 2 and ISO 27001 certifications
  • Payment processors compliant with PCI DSS standards
  • Analytics and monitoring tools with strict data processing agreements
We conduct regular security assessments of our third-party vendors and ensure they meet our stringent security requirements.

Merchant Responsibilities

While we implement robust security measures on our end, maintaining a secure environment is a shared responsibility. We recommend the following best practices for merchants:

  • Strong passwords: Use unique, complex passwords and enable two-factor authentication on your Shopify account.
  • Theme safety: Only install trusted apps and themes from verified sources to prevent security vulnerabilities.
  • Access control: Limit staff permissions to only what is necessary for their role and regularly review active users.
  • Updates: Keep your Shopify store and all installed apps up to date with the latest security patches.

Security Updates & Improvements

Security is not a one-time effort. We regularly review and update our security practices to address new threats and incorporate the latest industry standards. Updates to our security infrastructure are implemented seamlessly without disrupting your service.

We continuously invest in security infrastructure, conduct regular penetration testing, and stay informed about emerging threats to ensure EngageAI remains secure and trustworthy.

Security Inquiries

If you have questions about our security practices or wish to report a security concern, please contact us at:

support@liva7.com

We take all security reports seriously and will respond promptly to investigate and address any concerns.

This Security Policy may be updated periodically to reflect changes in our practices or regulatory requirements. We encourage you to review this page regularly to stay informed about how we protect your data. Continued use of EngageAI constitutes acceptance of the current Security Policy.