Security & Compliance

Built for a Regulated Industry, Not Retrofitted for One

You're entering counterparty data, negotiated rates, and compliance records into this system. Here is exactly how they're protected.

Tenant Isolation, Enforced at the Database

Every business record — accounts, orders, invoices, contracts, commission schedules — is scoped to your organization with row-level security enforced at the database layer, not just in the UI. There is no admin bypass: even a workspace owner of another tenant cannot read your negotiated rates, counterparties, or pipeline. Cross-party visibility (e.g. a buyer signing your PO) happens only through single-use, token-gated links served by backend functions that disclose exactly the fields needed.

License Verification You Can Audit

We never assert a license is valid — we prove a registry link. An account is only marked Verified when the matching pipeline resolves it to a live Michigan CRA registry record with matching name, address, and license type evidence. Ambiguous matches go to a human review queue, never to a green checkmark. Registry standing (active vs. prequalified vs. suspended) is parsed from specific CRA status codes, not treated as a boolean.

Append-Only Compliance History

Registry changes, ACH authorization mandates, order signatures, and command executions are written to append-only audit records with timestamps, actor identity, and source. A license that went active → revoked between two registry snapshots leaves a field-level change trail — exactly the evidence a compliance review asks for. Signatures capture signer name, IP address, and timestamp server-side.

Scoped Partner Access

External brokers, buyers, transporters, and co-packers never see your internal CRM. Brokers connect through the Representation Bridge and see only authorized line sheets. Buyers e-sign through expiring token links with no login. Transporters get a stripped logistics-only view once assigned. Financial snapshots (COGS, margins) are additionally restricted to admin users within your own org.

Payments & NACHA Compliance

ACH authorizations are captured as immutable NACHA mandate records: the full verbatim consent text, authorized amount, signer identity, IP, and timestamp — stamped server-side, never from the client. Bank account numbers are tokenized at the payment gateway and never stored in our database; we retain only the institution name and last four digits.

Your Data Is Yours

Full account data export is available on demand. Sample/demo data is clearly flagged and bulk-removable. If you leave, your book of business leaves with you.

Questions about our security posture?

We'll walk your compliance team through the architecture directly.