EagleLytics — Supplier Monitor

Built to be trusted.

Security & privacy

Your data is safe with EagleLytics®.

Store credentials encrypted at rest, sessions that cannot be read by browser scripts, verified webhooks and a crawler that follows the rules. Here is exactly what protects your account.

Secure by design

Authentication, credential storage and webhooks are built with defence in depth, not bolted on.

Least data

We store what monitoring needs — supplier product data and your store connection — not your customers’ personal data.

Transparent crawling

Every supplier request identifies itself as EagleLyticsBot/1.0 and respects the rules the supplier publishes.

Auditable

Security-relevant events are logged and watched, so unusual activity is noticed and acted on.

Security controls

Built to protect what matters.

Each control below is implemented in the EagleLytics® codebase and documented in our internal security handbook.

Account security

Your sign-in

httpOnly session cookies

Sessions use JSON Web Tokens stored in httpOnly cookies, so scripts in the browser cannot read them, with CSRF double-submit protection on every state-changing request.

Short-lived tokens, rotating refresh

Access tokens expire quickly and refresh tokens are single-use. Changing your password or email revokes every existing session immediately.

Email two-factor authentication

A one-time code is emailed at sign-in. Admin access to our internal panel requires a separate second factor.

Strong password hashing

Passwords are hashed with bcrypt and must be at least 12 characters with mixed case and a digit.

Account lockout

Repeated failed sign-in attempts temporarily lock the account to slow down credential guessing.

Rate limiting

Sign-in, verification, registration and password endpoints are rate limited per client.

Data protection

Your store credentials

Encrypted at rest

Store access tokens and API keys are encrypted with Fernet before they touch the database, with support for key rotation.

Verified webhooks

Shopify and Square webhooks are HMAC-verified with timing-safe comparison, and replayed events are detected and ignored.

SSRF protection

Every external URL you give us is validated before it is fetched: private networks and cloud metadata addresses are blocked.

Input validation

Request fields have length limits, request bodies are capped in size, and database queries are parameterised throughout.

XSS defences

User-provided HTML is sanitised on the server (bleach) and again in the browser (DOMPurify), backed by a Content Security Policy.

Security headers

Responses carry HSTS, X-Frame-Options, nosniff, Referrer-Policy and Permissions-Policy headers.

Platform & crawl compliance

How we behave on the web

robots.txt and crawl-delay

Supplier sites are checked against robots.txt before any scan, and crawl-delay directives are enforced with a per-domain rate limiter.

Identified user agent

Page crawls identify as EagleLyticsBot/1.0 so suppliers always know who is visiting and can whitelist or block us.

Audit logging and monitoring

Authentication and billing events are written to an audit log. A security monitor reviews it on a schedule and alerts administrators to suspicious patterns.

Privacy

Your choices

Consent management

Analytics and marketing tags load only after you consent, and Global Privacy Control signals are honoured automatically.

Shopify GDPR webhooks

The mandatory customer data request, customer redact and shop redact webhooks are implemented, so uninstalling removes your store’s data.

Account deletion

You can delete your account from your profile. Deletion cancels billing, removes your data in a safe order and revokes all sessions.

Privacy first

We respect your data.

EagleLytics® stores supplier product data and your store connection — nothing more than monitoring needs. What we collect, why, and how to opt out is written down in plain language.

  • Cookie consent before any analytics tag loads
  • Global Privacy Control honoured
  • No Shopify customer personal data stored
  • Delete your account at any time

Responsible disclosure

Found a security issue? Tell us first.

If you believe you have found a vulnerability in EagleLytics®, email us with the steps to reproduce it and give us a reasonable amount of time to investigate and fix it before sharing it publicly. Please do not access other people's data or disrupt the service while testing.

Related reading: Policies · Your privacy choices · Terms

Operate with confidence.

Monitor supplier inventory with EagleLytics® — securely and transparently.

No credit card required · 14-day free trial