Security

Your supplier data is safe with us

Enterprise-grade security built into every layer. Your pricing data, part numbers, and business information are encrypted, isolated, and never shared.

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Your supplier price lists and parsed data are protected at every stage.

Per-Account Data Isolation

Every query is scoped to your user ID. Your files, supplier data, and parsed results are completely invisible to other users — strict multi-tenant isolation.

Secure Authentication

Passwords are hashed with bcrypt. Sessions use JWT tokens with 7-day expiry. No plaintext credentials are ever stored or transmitted.

No Data Sharing or Mining

We never sell, share, or mine your supplier data. Your pricing information, part numbers, and business data stay private. Period.

Cloudflare Edge Infrastructure

Hosted on Cloudflare's global edge network with built-in DDoS protection, WAF, and automatic HTTPS. Enterprise-grade infrastructure at every layer.

GDPR & Privacy Compliance

We follow GDPR principles for data handling. You can request data export or deletion at any time. Our privacy policy is transparent and straightforward.

Our security commitments

  • We never sell or share your supplier data with third parties
  • All uploaded PDFs and generated CSVs are encrypted at rest
  • Strict per-user data isolation — no cross-account access
  • Stripe handles all payment processing (PCI DSS compliant)
  • You can request full data export or deletion at any time
  • Regular security reviews and dependency audits

Questions about security?

We're happy to discuss our security practices in detail.