Tenant and data separation
Tenant-scoped requests and repository operations are limited by tenant identity so records from different businesses do not mix.
Authentication, roles and permissions
Protected operations require authentication and role checks. Privileged bulk operations retain user and operation records.
Transport security and provider connections
Live service traffic uses HTTPS. Provider accounts and access data are configured by authorised users during connection setup.
Secrets and sensitive data
Backend secrets are not exposed to the client. Public client variables contain only public configuration, and credentials are not committed to source.
Auditability
Operation history and audit records cover critical areas such as product documents, media and bulk processing.
Human approval and automation controls
Customer approval is the order-creation boundary. Team members can take over, and errors, failures and retry results remain visible.
Data requests
Once a verified contact channel is configured, access, correction and deletion requests can be submitted through the contact page.
No ISO 27001, SOC 2 or PCI DSS certification is claimed.