PackPost 보안 사고 대응 정책

최종 수정일: 2026-09-11

이 문서는 PackPost 운영 중 보안 사고(무단 접근, 데이터 유출, 서비스 중단 등)가 발생했을 때 어떻게 탐지·대응·통지하는지를 설명합니다.

1. 적용 범위

판매자의 스토어 도메인, 배송 단계 설정, 주문 타임라인, 고객 이메일 등 PackPost가 Neon 데이터베이스와 Render 서버에 보관·처리하는 모든 데이터에 적용됩니다.

2. 사고 분류

3. 대응 절차

  1. 탐지 (즉시) — Render 대시보드의 로그/오류 알림 및 Neon 대시보드의 비정상 접근 알림을 통해 사고를 인지합니다.
  2. 격리 및 차단 (24시간 이내) — 유출/탈취가 의심되는 API 키, 데이터베이스 접속 정보, Shopify 앱 시크릿을 즉시 교체(rotate)하고, 필요 시 문제된 접근 경로를 차단합니다.
  3. 조사 — 로그를 분석해 영향을 받은 스토어와 데이터 범위(어떤 주문, 어떤 필드)를 특정합니다.
  4. 통지 (인지 후 72시간 이내) — 영향을 받은 스토어 운영자에게 이메일로 사고 개요, 영향 범위, 조치 사항을 안내합니다. 법적으로 요구되는 경우 관련 감독기관에도 통지합니다.
  5. 복구 — 원인이 된 취약점을 수정하고, 필요 시 백업(Neon PITR)에서 데이터를 복구합니다.
  6. 사후 검토 — 사고 원인과 대응 과정을 기록하고, 재발 방지를 위한 조치(권한 축소, 추가 로깅 등)를 적용합니다.

4. 예방 조치

5. 신고 방법

보안 취약점을 발견했거나 사고가 의심되는 경우 아래 이메일로 즉시 알려주세요. 가능한 한 빠르게 확인 후 대응하겠습니다.

보안 문의 / 사고 신고

이메일: shopboost.dev@gmail.com

PackPost · Shopify App

PackPost Security & Incident Response Policy

Last updated: 2026-09-11

This document explains how PackPost detects, responds to, and discloses security incidents (unauthorized access, data breach, service outage) affecting the app.

1. Scope

This policy covers all data PackPost stores and processes on Neon (database) and Render (application server): store domains, configured delivery stages, order timelines, and customer emails.

2. Incident Classification

3. Response Process

  1. Detection (immediate) — incidents are identified via Render dashboard log/error alerts and Neon dashboard anomaly notifications.
  2. Containment (within 24 hours) — any API key, database credential, or Shopify app secret suspected of compromise is rotated immediately, and the affected access path is blocked if needed.
  3. Investigation — logs are reviewed to determine which stores and which data fields were affected.
  4. Notification (within 72 hours of discovery) — affected store owners are emailed a summary of the incident, its scope, and remediation steps. Relevant authorities are notified where legally required.
  5. Recovery — the root cause is patched, and data is restored from backup (Neon point-in-time recovery) if necessary.
  6. Post-incident review — the cause and response are documented, and preventive measures (tighter access scopes, additional logging, etc.) are applied.

4. Preventive Measures

5. Reporting an Issue

If you discover a security vulnerability or suspect an incident, please contact us immediately at the email below. We will review and respond as quickly as possible.

Security Contact / Incident Reporting

Email: shopboost.dev@gmail.com