Skip to content

Security & Compliance

How we protect your data

We handle order, customer, and sales data for our clients. These are the controls that keep it separate, protected, and encrypted.

01Control

Data isolation

Every record belongs to one client organisation. Row level security rules in our Postgres database check each request against the signed-in user's organisation, so one client can never read or change another's data, even if application code has a bug.

  • Each record stores an organisation ID
  • Access is checked by the database on every query
  • Roles limit what each person can see within their organisation

02Control

Network protection

All public traffic is routed through Cloudflare before it reaches our hosting on Vercel. Requests are filtered by a web application firewall, rate-limited, and screened for bots and denial-of-service attacks.

  • Cloudflare web application firewall
  • DDoS protection and rate limiting
  • Servers accept traffic over HTTPS only

03Control

Encryption

Data is encrypted whenever it moves between systems and whenever it is stored, including backups.

  • TLS 1.2 or higher on every connection
  • AES-256 encryption for stored data
  • Encrypted, access-controlled backups

04Control

Staff access and audit

Our own staff get the least access they need to do their job, and every action on production systems is recorded.

  • Multi-factor authentication for all staff accounts
  • Support agents only see the systems and records assigned to them
  • Access to production is logged and reviewed

05Documents

Policies and agreements

Our policies are available to read here. Signed copies are available on request.

Next step

Have a security questionnaire?

Send it to us. Our team will complete it and walk your security reviewers through our setup.

Schedule a consultation
RESPONSE
2–4 business hours