Security
Your SKU demand history, supplier network records, and procurement data are operationally sensitive. We designed Supplyverde with controls that protect your data at rest, in transit, and from cross-tenant exposure. This page describes how those controls work. We do not claim certifications we have not completed.
Security practices
Data encryption at rest and in transit
All customer data is stored encrypted using AES-256. TLS 1.2 or higher is required for all data in transit. Certificates are managed and rotated on a defined schedule.
Tenant data isolation
Each customer's data is stored in isolated partitions. Our architecture is designed so that cross-tenant data access is not possible at the application or storage layer.
Access controls
Role-based access at the user level within each account. Platform administrators can review and manage user permissions. An audit log of user actions is available to account admins.
Authentication
Email and password authentication with bcrypt hashing. Passwords are never stored in plain text. Multi-factor authentication (MFA) support is on our near-term roadmap.
Responsible disclosure
If you discover a security vulnerability in Supplyverde, please report it to us directly before public disclosure. Send details to [email protected] with "Security Disclosure" in the subject line. We will acknowledge your report within 2 business days and work to address confirmed vulnerabilities promptly. We appreciate responsible disclosure and will work with you to understand and resolve the issue.