Security & Data Protection

How we handle your data

Authenticated access, company isolation, private file storage, controlled release and documented retention safeguards.

πŸ”

Access and transport security

Administrative and portal routes require an authenticated session and enforce role-based access. Sessions are separated between sites, and all sites are served over TLS.

🏒

Company isolation

Requests, result files, and messages are scoped to the company that owns them. Isolation is enforced server-side on every query.

πŸ“

Private storage and file integrity

Files are stored outside the public web root. Each stored file has a recorded checksum, and a file that no longer matches its record is refused.

πŸ›‘οΈ

Malware scanning and validation

Uploads are scanned before acceptance and validated for file type, size and row count. Macro-enabled workbooks (.xlsm) are rejected.

πŸ‘€

Expert review before release

Unclear or ambiguous items are marked β€œFOR HUMAN REVIEW.” An expert administrator reviews all results, resolves flagged items where possible, and releases the final output.

πŸ“

Audit evidence

Administrative actions, publication decisions and access to released material are recorded in an append-only audit log.

πŸ—‘οΈ

Retention and legal holds

Files and results are deleted automatically after 90 days unless a company-specific retention setting applies. Legal holds suspend automatic deletion until lifted.

πŸ“₯

Data minimisation

Screening considers the supplier name and item description. Pricing, quantities, buyer identity and contact details are not required for screening.

More information: See the Privacy Policy for the complete description of personal-data processing.

Questions about data handling?

We can explain the security controls and data-handling measures described on this page.

Talk to us β†’