Security controls should make catalog operations safer and more explainable.
The platform uses organization isolation, role/permission checks, private source storage, audit history and guarded processing controls. No unearned certification claims.
Tenant isolation
Customer application routes bind organization context and enforce active organization membership before tenant data is used.
Role-based permissions
Catalog, supplier, import, mapping, review and organization actions are protected by explicit permission middleware.
Private source data
Raw source files use private storage and downloads are protected by tenant authorization and signed URLs.
Auditability
Audit events, product source provenance, mapping versions and import state preserve operational evidence.
Connector secrets
Supported connector credentials are handled separately from ordinary configuration, and secret-like values are rejected from unencrypted configuration.
Processing safeguards
Import locking, idempotency controls, rollback integrity checks and mass-deletion protection reduce destructive failure modes.
Certification status
This page does not claim SOC 2, ISO 27001 or other certifications that have not been obtained. Deployment-specific controls such as infrastructure encryption, backups and incident procedures should be documented from the production environment rather than assumed.