Security & Separate Stores

The AI-first security model

Why a platform where AI helps run your stores faces security risks that traditional platforms never do, and how Reqursor Platform holds back every one of them.

When AI drafts changes to live stores, new kinds of risk appear that a platform run only by people never has to think about. This page explains what those risks are. It also explains the one safeguard that holds back every single one of them: the rule that every change is checked before it goes live, which is also what makes AI safe to use here in the first place.

The risks unique to an AI-first platform

RiskWhat could go wrongHow it's contained
Tricking the AI with what someone typesSomeone tries to make the AI ignore its instructions through what they type.Typed input is cleaned and organized before the AI sees it, so instructions stay separate from information.
Tricking the AI with hidden contentHarmful text hidden inside a store's content tries to steer the AI while it analyzes the store.The AI reads only the store's managed settings, never business content such as product descriptions.
Reaching into another agency's dataAn attempt to make the AI mention or pull in another agency's data.Every request is tied to exactly one agency. Any output that mentions something outside that agency is rejected, no matter what the AI produced.
Making the AI do something destructiveAn attempt to make the AI delete a store or change a credential (a stored password or access key).The AI can't see secrets, can't delete stores, and can never skip the step where you confirm a change.
Getting the AI to reveal internal detailsAn attempt to make the AI reveal technical details about how the platform runs.The AI never has access to secrets or technical details of the platform, so there is nothing to reveal.

The AI's output is never trusted blindly

Every response from the AI passes checks before it ever reaches your preview:

  • It has to follow the rules. Anything that doesn't match the expected format, or the rules of your store platform, is rejected outright.
  • It has to stay within your agency. Anything that mentions a store outside your agency is rejected by the platform, whatever the AI produced.
  • It has to be information, never instructions. The AI's answer is only ever read as information. It is never run as a command.

Even a perfect attack still needs your approval

If every other defense somehow failed, one safeguard would still hold: nothing the AI proposes ever reaches a live store without your explicit confirmation. See How the AI writes your store's setup safely for how that step works. It is the strongest safeguard on the platform, and it doesn't depend on any of the others working.

On the roadmap: AI shopping agents

The Reqursor Platform roadmap includes letting AI shopping agents (AI assistants that shop on a buyer's behalf) work with stores directly: reading product information and completing checkout. This is being designed with the same limits: they can only look at the catalog, they never see customer data or order history, and payment goes through the store's existing, already-secured payment service.

Why this matters for your agency

  • The AI suggests, it never acts. Even if someone manages to manipulate the AI, all it can produce is a suggestion. It can't change your store.
  • The safeguards don't depend on the AI behaving well. Checks, limits on what the AI can reach, and your confirmation are there because the platform assumes the AI might be wrong or manipulated.
  • One problem doesn't spread. Every request is limited to your own agency, so even a manipulated request can't reach beyond it.

Where to go next