Shopify hosts your store, but not all of your risk: malicious apps, hijacked staff accounts, brand phishing, tampered themes. The method differs; the standard does not.
Any one of these signals warrants triage. It costs €500 and you keep the diagnostic report — deducted from the fee if an engagement starts.
Confirmed compromise or false positive? Scope, exposed data, legal obligations. Engagement authorisation signed online, secure access established.
App and permission audit, store activity log, theme and scripts, staff accounts and multi-factor authentication, DNS and email configuration.
App and session revocation, credential rotation with mandatory multi-factor authentication, theme cleanup, phishing site takedown procedure.
Integrity probes and automated watch for 30 days, with an alert channel validated by a real end-to-end test.
Published rates, signed scope, best-efforts obligation stated in writing.
What is included, what is not →
Start an interventionFirst response from an engineer within 5 hours, Monday to Friday, 8am to 8pm. “Response” means talking to an engineer, not an automated acknowledgement.
Not before speaking with us. Shutting down destroys volatile evidence and does not remove persistence. We move the site into controlled maintenance instead.
You keep the diagnostic report and nothing else is billed. If you prefer, the amount paid becomes a credit towards preventive hardening.
No — and be wary of anyone who promises that. We are bound by a best-efforts obligation stated in the contract: industry standards, a defined scope, and 30 days of monitoring to verify the eradication holds.
Yes, as an option: we assemble remediation evidence in the expected format, file the review request and follow it through to removal of the flag — the same process applies to cyber insurance claims.
An engineer replies within 4 to 5 hours — within 4 hours for continuous-protection subscribers.
✉ [email protected] · [email protected]
Remote engagements across Europe — EN / FR / ES / IT / PT / PL / HU / CS