Controls
Security model
- OAuth scopes are shown on a user-facing consent screen.
- Platform identity does not bypass merchant-specific verification.
- Server-side validation runs for tool inputs, not just client-side shaping.
- Suspicious activity is rate-limited and can be filtered or blocked.
Components
Apps SDK iframe posture
Clawviyo’s app components are self-contained HTML responses with restrictive response headers, including a dedicated Content Security Policy. They do not depend on broad third-party script execution to render core UI.
Reporting
Questions or security concerns
To report a security issue or request implementation details needed for enterprise or reviewer validation, contact [email protected] and reference the platform app endpoint.
Reviewer note: If you need demo credentials, seeded merchants, or a prompt pack to validate the platform connector, use the support page.