Your supply chain data runs through this platform. Here is how it is encrypted, isolated, logged, and returned to you.
Encrypted in transit and at rest. Tenant separation is enforced by the database itself, through row-level security.
Encryption in transit
TLS 1.2 minimum and TLS 1.3 where supported, with HSTS enforced on customer-facing endpoints. Applies between your systems and the platform, and between the platform and every carrier, ERP, and warehouse system it connects to.
Encryption at rest
AES-256 across the database and object storage, applied by the infrastructure layer.
Tenant isolation
Enforced by row-level security in the database, with separate application and administrative database users. A query that omits the tenant filter returns no rows.
Control who can reach your data and what they can do with it. Every action is written to the audit log.
Single sign-on
SAML 2.0 and OIDC against your identity provider, through Auth0. Available on Enterprise plans.
Multi-factor authentication
Available through Auth0, with password policy, brute-force protection, and session controls. Enrollment is per user; account-wide requirements are set up with us during onboarding.
Role-based access control
Granular permissions by role, down to which operations a user can run and which data they can read.
API key management
Create, rotate, and scope keys, and track usage per key. Revoking a key takes effect immediately.
Sub-account isolation
Separate client data into sub-accounts with their own users and permissions. Available on Enterprise plans.
Audit logging
Every user action, API call, and system event is recorded with actor, timestamp, and what changed.
Agents act across your operations. These are the limits on what they can see and do.
Personal data does not train models
Training on customer inputs is opt-in. By default, we do not train models on personal data, and our AI providers' enterprise terms exclude those inputs from their training. Aggregated, de-identified data may be used to improve the platform and our models, as described in the Terms and Privacy Policy.
Agent audit trail
Every agent decision is logged with the reasoning behind it and the actions it took, exportable for compliance review.
Approval before action
Guardrails and a policy engine decide what an agent may do on its own. Anything above the threshold you set waits for a user to approve it.
Model choice
Run agents on Claude or OpenAI, or bring your own provider credentials on Enterprise plans. View the model providers we use on our subprocessor list.
Where the platform runs, how it is monitored, and what happens when issues arise.
Cloud infrastructure
Hosted on Google Cloud Platform in the United States, with health, latency, and availability monitored against internal service level objectives.
Incident response
Documented severity levels and escalation paths. Security incidents are notified to affected customers within 72 hours of becoming aware, per the data processing agreement.
Availability commitment
A contractual uptime SLA is included on Enterprise plans. Everyone runs on the same infrastructure and the same monitoring.
Change management
Production changes go through pull requests against the main branch, so every change is tracked in version control with its author and its diff. Emergency fixes are narrowly scoped.
Secure development
Dependency scanning and static analysis run against the main codebase, and critical findings are triaged when they surface. Inbound webhooks are verified by HMAC signature with timing-safe comparison, and every tenant is rate limited.
Certification status, and the agreements that cover data protection, transfers, and ownership.
SOC 2 Type II
Pursuing certification for security, availability, and confidentiality. Controls are mapped and evidence is being collected against the audit window.
GDPR and data transfers
A data processing agreement with Standard Contractual Clauses and the UK addendum is available for EU and UK customers.
Data ownership and retention
Configurable retention policies. You own your data, can export it at any time, and can have it deleted on request. See the privacy policy.
Our security policy, SOC 2 evidence, and completed questionnaires are available on request.