What we hold, what we do, and what we'll show you.
ISO/IEC 27001 certified and SOC 2 Type II audited. Both reports available under NDA.
- ISO/IEC 27001 — certified.
- SOC 2 Type II — audited, report available for review.
- A formal ISMS behind both, not a policy folder.
- We don't sell supplier data.
How security is run here
We operate a formal Information Security Management System. Documented policies, a defined risk assessment and treatment process, continuous monitoring, an incident response procedure, and internal and external audits on a schedule.
That is the difference between being certified and being secure — the certificate says the system exists and works, not that somebody wrote a policy once.
Access and permissions
- Role-based permissions, so people see the records their job requires.
- Separation of duties on the actions that matter — bank detail changes need two approvals.
- Administrative access controlled and logged.
- User actions and system changes auditable.
Your data
We don't sell supplier data.
Supplier and buyer data is handled under role-based access control, and data sharing is limited to what onboarding and governance actually require.
The audit trail
Every supplier data submission, document upload, review, approval and status change is retained with a timestamp and an identity attached.
When an internal auditor or an external one asks who approved a supplier and on what evidence, the record answers it.
If you leave, we retain your data for 90 days and then remove it.
Due diligence
SOC 2 Type II reports and ISO 27001 certification detail are provided as part of security review. Ask and we'll send them.