Encryption everywhere
AES-GCM at rest and TLS 1.2+ in transit (TLS 1.3 where supported). Supplier delivery credentials are encrypted with AES-256-GCM authenticated encryption and never written to application logs.
AES-GCM at rest and TLS 1.2+ in transit (TLS 1.3 where supported). Supplier delivery credentials are encrypted with AES-256-GCM authenticated encryption and never written to application logs.
All order data is processed and stored in EU-region infrastructure. No data leaves the region without an explicit, contracted subprocessor agreement.
Every parse, edit, validation and delivery attempt is recorded in an append-only audit log. Export the full delivery log for any order at any time.
Per-supplier rules block malformed orders before they ever reach a supplier endpoint — wrong currency, missing fields, unresolved codes.
Org-scoped data isolation on every query, scoped API keys you can revoke instantly, and short-lived sessions by default. Role-based access and SAML/OIDC SSO are available on Enterprise — we set them up with you during onboarding.
Mapping suggestions never auto-apply without a confidence score and source. Your data is never used to train third-party models. Enterprise customers can opt into a self-hosted, no-egress mode where document extraction — including scanned-PDF OCR — runs entirely in your environment, with nothing sent to OpenAI.
Full list with locations, contracts, and change notifications: /subprocessors
We'll share our DPA, security overview, and architecture documentation under NDA.