Skip to main content
Security & trust

Built for orders you can't afford to get wrong

ProcuLink sits between your buyers and suppliers. We treat that position — and your data — with the seriousness it deserves.

Encryption in transit and at rest

Supplier delivery credentials are encrypted at rest with AES-256-GCM authenticated encryption and are never written to application logs. Every outbound channel configured by URL — webhook and HTTP delivery, the ERP connectors on Enterprise plan and up, catalog feeds and S3 ingestion — must use https://, and a plain http:// address is refused when you save it. SFTP is encrypted by construction, and FTPS negotiates explicit TLS. Two connection settings can still weaken that if you switch them on: skipping FTPS certificate validation, and turning SSL off for IMAP or SMTP.

Where your data lives

Your order files, the database behind them, and the API all run in EU-region infrastructure — Cloudflare R2, Neon, and Railway. Some processing runs on named US subprocessors under standard contractual clauses: sign-in, AI document extraction and mapping suggestions, payments, and email in both directions — the orders your suppliers email in, and the purchase orders we email out to them. If you deliver an order by email, the order itself passes through a US provider. Each one is listed with its location and contract on /subprocessors. Where your data is stored and the route it travels are two different questions: the network path out to your supplier is chosen by our hosting provider and is not pinned to a region by us, so we cannot tell you today which country an outbound delivery leaves from.

What we record for every delivery

Every parse, edit, validation and delivery attempt is recorded. Each delivery attempt carries its timestamp, channel, endpoint, attempt number, response code, and the SHA-256 fingerprint of the bytes dispatched; on channels that return one — webhook, email API, ERP — a failed or rejected attempt also stores the supplier's response. A retry adds a new numbered attempt rather than replacing the previous one, and requeueing supersedes earlier attempts rather than erasing them. You can open any single order and read its complete history on every plan; the workspace-wide delivery log across all orders, with filtering and CSV export, is included from the Operations plan up.

Validation before delivery

Built-in checks run on every plan and cannot be switched off: an order needs a PO number and a currency, every line needs a quantity above zero and a unit price that is not negative, and immediately before an order is transformed it is held back rather than emitted if a line is still flagged for review or its supplier item code is unresolved. Checks of your own for a supplier — an accepted currency list, a required ship-to or incoterm, a value range — are a separate versioned acceptance profile: authoring a version and activating one are both Enterprise plan and up, while reading the versions you already have is not gated, so a workspace that downgrades can still see what its suppliers enforce.

Access control

Org-scoped data isolation on every query, scoped API keys you can revoke instantly, and short-lived sessions by default.

Responsible AI

Mapping suggestions never auto-apply without a confidence score and source. Your data is never used to train third-party models. We can also turn AI extraction off for an organisation entirely, so nothing about its orders reaches OpenAI: the AI steps are switched off, our own parsers do the reading, and anything they cannot read is left for manual entry rather than sent out. We set that for you on request; it is not a self-serve setting, and it does not change where your files are stored.

Compliance

GDPRDPA published · SCCs for transfers outside the EEA
SOC 2Readiness on our roadmap
ISO 27001On our roadmap

Subprocessors

RailwayAPI and background-worker hosting
NeonPostgreSQL database hosting
CloudflareR2 object storage (order files and the output files we generate) and DNS
VercelWebsite and app hosting (order files do not pass through it)
ClerkAuthentication and session management
OpenAIAI document extraction and mapping suggestions (API data is not used for model training under OpenAI's API terms)
StripePayment processing and subscription management
PostmarkEmail in and out: orders emailed to your ProcuLink address, and the purchase orders we email to your suppliers
PostHogPseudonymous product analytics
SentryError monitoring and diagnostics

Full list with locations, contracts, and change notifications: /subprocessors

Need our security package?

We'll share our DPA, security overview, and architecture documentation under NDA.