How we handle your data
Authenticated access, company isolation, private file storage, controlled release and documented retention safeguards.
Access and transport security
Administrative and portal routes require an authenticated session and enforce role-based access. Sessions are separated between sites, and all sites are served over TLS.
Company isolation
Requests, result files, and messages are scoped to the company that owns them. Isolation is enforced server-side on every query.
Private storage and file integrity
Files are stored outside the public web root. Each stored file has a recorded checksum, and a file that no longer matches its record is refused.
Malware scanning and validation
Uploads are scanned before acceptance and validated for file type, size and row count. Macro-enabled workbooks (.xlsm) are rejected.
Expert review before release
Unclear or ambiguous items are marked βFOR HUMAN REVIEW.β An expert administrator reviews all results, resolves flagged items where possible, and releases the final output.
Audit evidence
Administrative actions, publication decisions and access to released material are recorded in an append-only audit log.
Retention and legal holds
Files and results are deleted automatically after 90 days unless a company-specific retention setting applies. Legal holds suspend automatic deletion until lifted.
Data minimisation
Screening considers the supplier name and item description. Pricing, quantities, buyer identity and contact details are not required for screening.
Questions about data handling?
We can explain the security controls and data-handling measures described on this page.