CS ComplyStream
Toggle menu

Security at ComplyStream

FBR credentials and customer order data deserve boring, explicit controls—not a claim that anything connected to the internet is “100% secure”.

FBR token protection

Sandbox and production tokens are stored encrypted at rest and used server-side for requests made for the connected shop. The ordinary app interface does not display a saved token in full. Tokens should not be placed in support messages, screenshots or client-side theme code.

Shopify access

Access begins through Shopify's app installation and permission flow. ComplyStream requests data needed for invoice preparation and operation; Shopify store owners remain responsible for staff permissions. Uninstalling revokes the app's Shopify access under Shopify's platform process.

Data isolation and transport

Merchant records and credentials are associated with the relevant shop. Application and external API traffic is sent over encrypted network connections where supported. We limit production access operationally and avoid using live customer records for casual testing.

Logging without leaking secrets

Operational logs are needed to diagnose timeouts, rejected fields and duplicate attempts. Secrets should be redacted from logs and support output. Invoice responses may still contain business or buyer information, so access is limited to the people and systems needed to operate support.

Revoking access

  • Rotate a sandbox or production token through the applicable IRIS/integrator process.
  • Replace the token in ComplyStream when continued use is intended.
  • Uninstall the Shopify app to revoke store access.
  • Remove staff who no longer need access to app screens.

Our licensed-integrator boundary

ComplyStream is not an FBR-licensed integrator. It is workflow software that uses credentials configured for the merchant's selected integrator relationship. That separation matters for both security and accountability: we do not provide a shared NTN, token or IRIS identity.

Reporting a concern

Email support@complystream.pk with a concise description, affected store and safe reproduction steps. Do not include a live token or unnecessary CNIC data. For an active credential concern, rotate the credential first and then contact us.

Last updated: 4 August 2026

Not tax advice. Confirm registration scope, rates, deadlines, and filing obligations with a Pakistani tax practitioner against current FBR SROs and the Sales Tax Act. ComplyStream is not affiliated with FBR or PRAL.

Need to discuss a security question?

Contact us without sending credentials or sensitive customer data.