4.1 What Sketch Audit does
Sketch Audit scans your Shopify store theme for:
- Malicious scripts and code injection — code patterns associated with skimmers, trojans, or known malware
- Hidden checkout overlays and card skimmers — invisible elements that capture payment information
- Unexpected code changes to your theme — files that differ from your previous scan baseline
- Suspicious domains and URLs — scripts or links pointing to known malicious or untrusted external domains
How we detect suspicious domains:
- Comparison against industry-standard threat intelligence and malware databases
- Identification of obfuscated or encoded URLs
- Detection of domains used in past skimming campaigns
- Flagging of uncommon TLDs or recently registered domains in payment-critical code
Limitations:
- New domains not yet in malware databases may not be flagged
- Legitimate third-party services may share characteristics with malicious domains
- Context matters — a domain’s legitimacy depends on where it’s used in your code
4.2 What Sketch Audit does not do
Sketch Audit is a detection tool, not a guarantee of security. We do not:
- Automatically fix detected threats
- Prevent all malware or compromises
- Monitor network traffic or customer data
- Replace Shopify’s built-in security
- Guarantee a 100% detection rate
- Monitor apps or Shopify admin accounts
4.3 Service limitations
- Nightly scans: run once per day, typically between 2–4 AM UTC
- On-demand scans: Basic: none (nightly only); Pro: 30 scans per month
- Scan results: retained for 7 days (Basic and Pro)
- Detection quality: depends on code patterns, threat databases, and AI analysis
- Uptime: we aim for 99.9% uptime but do not guarantee zero downtime
4.4 Fair usage policy
On-demand scans are subject to fair usage limits. We reserve the right to throttle, suspend, or limit access if a single shop’s usage patterns are determined to be unreasonable, including but not limited to automated abuse, bot activity, commercial resale, or use for purposes other than security monitoring of your own store.
Enforcement: if we identify fair usage violations, we may take any of the following actions at our discretion:
- Notify you of excessive usage and request reduction
- Throttle API responses or limit scan frequency
- Temporarily or permanently suspend on-demand scanning
- Discuss custom solutions based on your specific situation
We will notify you when enforcement actions are taken.
4.5 SMS alerts and carrier charges
SMS alerts are included in the Pro plan (opt-in required).
What you’ll receive: SMS alerts are sent only when a theme scan detects a suspected malicious code or security problem that requires your attention. We do not send SMS for:
- All-clear scan results
- Marketing messages or promotional offers
- General notifications or feature announcements
- Scheduled reminders
An “alert” is defined as a Sketch Audit detection of suspected malicious code, hidden overlays, unauthorized modifications, or other security threats in your store theme.
Opt-in: SMS alerts require explicit consent and phone verification. To receive SMS alerts, you must:
- Check the consent checkbox agreeing to receive SMS alerts
- Enter and verify your phone number with a 4-digit code
- Save SMS settings
SMS alerts are disabled by default. Phone verification alone does not enable SMS — both the consent checkbox and verification are required.
Carrier charges: you may incur charges from your mobile carrier for SMS messaging. Sketch Audit is not responsible for SMS messaging rates charged by your carrier, data usage from receiving SMS notifications, delivery delays or failures from your carrier, or carrier blocking or filtering of SMS messages.
You can disable SMS alerts anytime in your dashboard settings. Standard SMS message and data rates apply based on your carrier’s plan. Reply “STOP” to any SMS to unsubscribe from alerts.
4.6 Acceptable use
You agree not to:
- Use Sketch Audit to scan stores you do not own or operate
- Attempt to reverse-engineer, decompile, or modify the App
- Use the App for any illegal or harmful purpose
- Circumvent rate limits or abuse the scanning feature
- Share your App access token with unauthorized users
- Use the App to scan non-Shopify stores or websites
- Resell, redistribute, or commercialize the App’s functionality