Security

Built to hold other people's data.

Our business runs on supplier data. These are the controls that protect it.

Credentials and access

Secrets stay server-side
Supplier API keys and tokens live in server-side secret storage only. They never ship in client code, extensions or mobile apps, and never appear in a logged URL.
Least privilege
People and services get exactly the access their role needs. Access is reviewed whenever a role changes.
Scoped partner keys
Keys we issue are scoped per partner and per dataset, and can be rotated or revoked at any time.

Data handling

Encrypted in transit
All traffic to and from the platform is TLS. No exceptions.
Separation by source
Each supplier's data is tagged and stored separately, with access controlled per source.
Data minimisation
We request only the fields we use, and keep them only as long as the terms allow.

Engineering practice

Deterministic engine
Calculations are deterministic and use exact decimal arithmetic, so any result can be reproduced and audited.
Regression-tested releases
Every engine release must reproduce a library of recorded cases exactly, or it doesn't ship.
Reviewed changes
Changes go through version control and automated checks before they reach production.
Due diligence

Send us your questionnaire

We don't yet hold formal certifications. We complete security questionnaires and walk reviewers through our controls directly.

Responsible disclosure

Found a vulnerability?

Email the details and steps to reproduce. We acknowledge every report, keep you updated, and take no action against good-faith research.

Contact

Reviewing us? Start here.

Security and compliance teams get direct answers from the people who built the platform.

Apply for access or