Make the trust boundary visible.
Blokk runs its own assessment service and PostgreSQL storage. It does not forward detection telemetry to an external bot-scoring API.
Separate access and separate evidence.
Generic API credentials are scoped to a site. Merchant access is validated against the Shopify shop and remains separate from the operator console. A shop query parameter is not authentication. Signed Shopify messages establish origin; they do not establish that an underlying visitor is legitimate.
Credentials stay on the server.
Generic API keys and operator sessions are stored as hashes. Shopify credentials require encryption at rest and shop-bound access. Public scripts contain no merchant access token, account-pseudonym secret or operator credential. Operator access retains its separate sign-in and deployment IP allowlist.
Collect what the action needs.
Bounded schemas restrict ingestion. We exclude form contents, passwords, card numbers, CVC and raw keystrokes from detection. Interaction telemetry is off by default. Browser observations remain untrusted; absence or consent delay alone does not indicate automation.
Keep identity scoped.
Authenticated account references use site-scoped pseudonyms. The release does not track people across customers or reuse customer events to train or tune rules for other customers. A browser-supplied customer ID is not authenticated identity.
Retention and recovery are operational controls.
Existing retention jobs, outcome correction history and deletion workflows remain part of the service. Shopify privacy and uninstall handling must be validated for each live pilot configuration. Backups and restores require the documented deletion reconciliation. See the data inventory and retention notice.
What has not been established.
This alpha has no SOC 2 or other security certification, independent audit, uptime history or service-level guarantee. Controlled tests do not establish production readiness. Public distribution, live-store coverage tests and reviewed legal details remain gates.
Contact and responsible reporting
g@blokk.bot. Do not send credentials, customer records or exploit traffic through the pilot request form. Only test systems you are authorised to test.