Security and trust

Enterprise controls without enterprise theater.

The production target is defense in depth: strong tenant boundaries, least privilege, auditable actions, resilient payments and tested recovery. Controls are activated as each production dependency comes online.

Tenant isolation

Every operator record is scoped to an organization and location. Tenant context is resolved server side and never trusted from browser supplied role data.

Least privilege

Owners, managers, dispatchers, processors, pressers, drivers, support and analysts receive only the permissions their work requires.

Auditability

Sensitive changes are designed to append actor, request and entity history so administrative actions can be investigated.

Payment separation

Payment credentials stay with the payment provider. Direct operator orders and future marketplace orders use separate funds flow policies.

API safety

Idempotency keys, webhook replay protection, scoped API keys, rate limiting and request identifiers are part of the production architecture.

Recovery

Production readiness includes point in time database recovery, tested restores, encrypted secrets, object retention rules and incident playbooks.

Portability

Operators should be able to export their business data instead of being trapped by software lock in.

Privacy

Customer consent, retention and deletion workflows are treated as product requirements rather than paperwork added later.

Founding operator program

Security claims will be evidence based.

We will not advertise certifications, uptime commitments or controls that have not been implemented and verified. The roadmap includes automated security testing, restore exercises, monitoring and documented incident response before general availability.

Request founding access