Security
The thing that would end this product is one supplier seeing another supplier's data
So we designed around that first, before anything else.
Controls
- 01Every request from a supplier is scoped to both your company and their vendor record. A query without that scope fails rather than returning data.
- 02Suppliers are never users of your administrative application. Separate application, separate identity, separate permissions.
- 03Passwordless sign-in to verified addresses, with one-time invitation links and immediate revocation.
- 04Full tax identification numbers are not stored in our application database.
- 05Banking details and sensitive documents are encrypted with a key scoped to your company.
- 06Documents are private and delivered only through short-lived links.
- 07Banking changes require re-verification and are never accepted by email alone.
- 08Action links in email are single-use, expire quickly, and are scoped to one action on one order. They are not credentials.
- 09Clicking a link never changes anything by itself. Corporate email scanners open links automatically, so every action requires a deliberate confirmation step — your purchase orders can never confirm themselves.
- 10The AI dialog can only propose changes within the order it was opened for. It cannot be talked into another supplier's data, because its scope comes from the signed link, not from the conversation.
- 11Every dialog transcript and email reply is stored alongside the change it produced, so there is always a record of why a date moved.
- 12Every supplier action, buyer action, and support access is logged.
Current status
We have not yet completed a third-party penetration test or a SOC 2 audit. The controls above describe what is built and enforced in the product today; they are not a certification. Ask us for our current control descriptions and testing plan before you connect.
Responsible disclosure
If you believe you've found a vulnerability, contact us through the contact page with "Security review" as the topic. We acknowledge reports within two business days.

