One page for a security review, your DPO, and procurement: where your store data lives, who can approve a change to your store, and the audit trail behind every automation. Nothing on this page you can't already find across the site.
Collaudo runs on AWS in the EU region. There is no transfer outside the EU for the service to operate.
A dry run before every change is the core governance control. The automation runs against your real catalog with every write held. Nothing touches the store until someone reads the report and approves it.
A full rehearsal of your automation against real store data, with every write captured and held instead of applied.
Until a dry run has passed. It is not a policy anyone can wave through: it is a product mechanic.
Automations that write to your store are held in dry-run mode until a person on your team approves them.
Every automation that writes to your store produces a dry-run report, and every deployment records who approved it. These double as processing records you can hand to an auditor.
Every change to the automation code is versioned, so you can see what ran, restore an earlier version in one click, and account for the change later.
Collaudo reaches only the data your automations need, through scopes you grant, and it proposes changes rather than applying them.
AI-written code touching a live store should be held to a higher bar than human-written code. It is.
Deploy stays locked until a dry run has passed. Not a policy, a product mechanic.
Dangerous operations are blocked on the server, not just hidden in the UI.
Each automation asks only for the API scopes it actually needs, when it needs them.
An automation that starts misbehaving is paused automatically, and you get an alert.
Every change to the code is versioned. Restore any earlier version in one click.
Your automations run sandboxed on AWS in the EU.
In the EU. Each store gets dedicated AWS infrastructure in eu-central-1 (Frankfurt), and your store data is processed in the EU. No transfer outside the EU is required for the service to operate.
Yes. A signed Data Processing Agreement is available on request on any paid plan. In it, you (the merchant) are the data controller and WMIE is the data processor, with processing limited to what your automations need.
A person on your team. Every automation that writes to your store is held in dry-run mode until a human reads the mutation report and approves it. Each deployment records who approved it and when, so you keep a full audit trail.
It is paused automatically and you get an alert. Deploy also stays locked until a dry run has passed, dangerous operations are blocked on the server, and every version of the code is kept so you can restore an earlier one in one click.
Only the Shopify data reachable through the API scopes you explicitly grant at install: products, prices, inventory, and whatever each automation you set up needs. Each automation asks only for the scopes it needs, and we do not sell your data.
AWS hosts and runs your automations, in the EU region. This website and its media run on Vercel, transactional email goes through Resend, and Google Tag Manager loads only after you consent to it. A current list of sub-processors is available on request, and we notify you before adding or replacing one.
AI writes real Python or TypeScript, a dry run rehearses it, you approve, it deploys.
Free plan · no card · 🇪🇺 EU data residency