Security overview

Least privilege, explicit consent, and verified write flows.

Clawviyo treats connector access as production traffic. The platform uses explicit scope consent, merchant-specific verification for write actions, server-side validation, and isolated app components with a restrictive content security policy.

Security model

  • OAuth scopes are shown on a user-facing consent screen.
  • Platform identity does not bypass merchant-specific verification.
  • Server-side validation runs for tool inputs, not just client-side shaping.
  • Suspicious activity is rate-limited and can be filtered or blocked.

Apps SDK iframe posture

Clawviyo’s app components are self-contained HTML responses with restrictive response headers, including a dedicated Content Security Policy. They do not depend on broad third-party script execution to render core UI.

Questions or security concerns

To report a security issue or request implementation details needed for enterprise or reviewer validation, contact [email protected] and reference the platform app endpoint.

Reviewer note: If you need demo credentials, seeded merchants, or a prompt pack to validate the platform connector, use the support page.