1. Home
  2. Shopify faq
  3. Are Shopify sites secure?

Are Shopify sites secure?

When you entrust your e-commerce platform, and therefore a large part of your turnover, to a SaaS platform, it is legitimate to ask the question of security.


So, is Shopify a solution you can trust ? Can you trust Shopify's security? Are there any risks of hacking or data theft? Are there any security breaches? Let's see if Shopify has all the arguments you need to entrust it with an e-commerce site.


Absolute security does not exist on the internet.

Hacking A quick note before attacking: absolute security does not exist on the internet. It is always possible to hack or attack a site or service. It all depends on the means the attacker is willing to employ.

This observation is important for understanding how security is measured on a website, whether e-commerce or not. The philosophy of internet security is certainly to protect yourself, but also to know how to react in the event of an attack.


More secure than open source?

Second, you need to see what you're comparing it to. SaaS is generally compared to open source. So, is Shopify more secure than an open source solution? This is one of the questions merchants often ask themselves when comparing Prestashop vs. Shopify .



Well, generally yes, for one simple reason: updates. Even if solutions like Prestashop or Magento are regularly updated, it is relatively difficult for a customer today to make all the updates required by open source solutions:

  • Server Updates
  • Server Application Update
  • Update of the e-commerce solution
  • Updating plugins / apps / extensions

And this is the main difference between Shopify and other solutions. Shopify is more secure because you don't need to worry about updates. They are done by the Shopify team and deployed "silently".

Whereas with open source, it's up to you or your IT service provider or e-commerce agency to update. So it costs a lot of money and many sites don't update.


However, without updates, it's impossible to secure a site or server. This creates numerous security vulnerabilities. Here's what one of the pro open source developers wrote on his own blog:

Prestashop security flaw

And he's right! In fact, the security company Sucuri conducted a study on different e-commerce CMS and was able to see that 97.2% of Prestashop and 83.1% of Magento were not up to date and had security flaws!

Open Source Security Vulnerabilities

Shopify is an extremely well-protected tool

Using Shopify for your online store makes your life easier by entrusting the management of this problem to a global player who has many more ways of monitoring what is happening on all of its sites than you do.

For example, managing free SSL certificates on Shopify's side helps you avoid forgetting to renew them and secures all stores with a very good level of protection.

But what would happen if Shopify were hacked? Well, if there are data leaks, the law requires Shopify to communicate precisely about the events and the stolen data. You will therefore be notified. Remember that if your Magento is hacked, no one will come and warn you; it is up to you to take responsibility.

Safety is, above all, a human issue.

But let's also be realistic, you don't need a security breach or an outdated site to get hacked. In fact, security problems generally come from humans. As a joke, in computer security it is often said that the main security breach is located between the keyboard and the chair (understand the human). Yes, that sounds like a geek joke.

In short, security is everyone's business: don't display your passwords on post-its, don't share them with service providers, change passwords regularly, don't use the same one everywhere.

These guidelines are valid for security purposes whether you use Shopify or not!

Auteur
Benoit Gaillat

Back to blog
2 comments

Bonjour Guichard, malheuresement , je n’ai pas compris votre question sur Shopify ?

Benoit Gaillat

Est ce que Hattyrs est un site sur?

Guichard
Leave a comment

Please note, comments need to be approved before they are published.

Derniers articles E-commerce