PackPost 보안 사고 대응 정책
이 문서는 PackPost 운영 중 보안 사고(무단 접근, 데이터 유출, 서비스 중단 등)가 발생했을 때 어떻게 탐지·대응·통지하는지를 설명합니다.
1. 적용 범위
판매자의 스토어 도메인, 배송 단계 설정, 주문 타임라인, 고객 이메일 등 PackPost가 Neon 데이터베이스와 Render 서버에 보관·처리하는 모든 데이터에 적용됩니다.
2. 사고 분류
- 데이터 유출 — 저장된 이메일, 주문 정보 등이 권한 없는 제3자에게 노출된 경우
- 무단 접근 — API 키, 데이터베이스 접속 정보, 관리자 계정 등이 탈취되어 시스템에 비정상 접근이 발생한 경우
- 서비스 중단 — 웹훅 처리 실패, 서버 다운 등으로 배송 현황 업데이트/조회가 불가능한 경우
3. 대응 절차
- 탐지 (즉시) — Render 대시보드의 로그/오류 알림 및 Neon 대시보드의 비정상 접근 알림을 통해 사고를 인지합니다.
- 격리 및 차단 (24시간 이내) — 유출/탈취가 의심되는 API 키, 데이터베이스 접속 정보, Shopify 앱 시크릿을 즉시 교체(rotate)하고, 필요 시 문제된 접근 경로를 차단합니다.
- 조사 — 로그를 분석해 영향을 받은 스토어와 데이터 범위(어떤 주문, 어떤 필드)를 특정합니다.
- 통지 (인지 후 72시간 이내) — 영향을 받은 스토어 운영자에게 이메일로 사고 개요, 영향 범위, 조치 사항을 안내합니다. 법적으로 요구되는 경우 관련 감독기관에도 통지합니다.
- 복구 — 원인이 된 취약점을 수정하고, 필요 시 백업(Neon PITR)에서 데이터를 복구합니다.
- 사후 검토 — 사고 원인과 대응 과정을 기록하고, 재발 방지를 위한 조치(권한 축소, 추가 로깅 등)를 적용합니다.
4. 예방 조치
- 모든 통신은 HTTPS(TLS)로 암호화되며, 저장 데이터도 암호화됩니다.
- 데이터베이스 접속 정보와 Shopify 앱 시크릿은 환경 변수로만 관리하며 코드에 포함하지 않습니다.
- 운영 계정(Neon, Render, Shopify Partners)에는 2단계 인증(2FA)을 사용합니다.
- 테스트/개발 환경과 운영(프로덕션) 데이터베이스를 분리해서 사용합니다.
- Render의 기본 요청 로그를 통해 관리자 화면 및 App Proxy 접근 이력을 확인할 수 있습니다.
5. 신고 방법
보안 취약점을 발견했거나 사고가 의심되는 경우 아래 이메일로 즉시 알려주세요. 가능한 한 빠르게 확인 후 대응하겠습니다.
보안 문의 / 사고 신고
PackPost Security & Incident Response Policy
This document explains how PackPost detects, responds to, and discloses security incidents (unauthorized access, data breach, service outage) affecting the app.
1. Scope
This policy covers all data PackPost stores and processes on Neon (database) and Render (application server): store domains, configured delivery stages, order timelines, and customer emails.
2. Incident Classification
- Data breach — stored emails or order data exposed to an unauthorized party
- Unauthorized access — compromised API keys, database credentials, or admin accounts leading to abnormal system access
- Service outage — webhook processing failures or server downtime that prevent delivery status updates or lookups
3. Response Process
- Detection (immediate) — incidents are identified via Render dashboard log/error alerts and Neon dashboard anomaly notifications.
- Containment (within 24 hours) — any API key, database credential, or Shopify app secret suspected of compromise is rotated immediately, and the affected access path is blocked if needed.
- Investigation — logs are reviewed to determine which stores and which data fields were affected.
- Notification (within 72 hours of discovery) — affected store owners are emailed a summary of the incident, its scope, and remediation steps. Relevant authorities are notified where legally required.
- Recovery — the root cause is patched, and data is restored from backup (Neon point-in-time recovery) if necessary.
- Post-incident review — the cause and response are documented, and preventive measures (tighter access scopes, additional logging, etc.) are applied.
4. Preventive Measures
- All traffic is encrypted via HTTPS (TLS); stored data is encrypted at rest.
- Database credentials and Shopify app secrets are kept only in environment variables, never committed to source code.
- Two-factor authentication (2FA) is used on operational accounts (Neon, Render, Shopify Partners).
- Development/test and production databases are kept separate.
- Render's default request logging provides a record of access to the admin screen and App Proxy endpoints.
5. Reporting an Issue
If you discover a security vulnerability or suspect an incident, please contact us immediately at the email below. We will review and respond as quickly as possible.
Security Contact / Incident Reporting
Email: shopboost.dev@gmail.com