Tenant and customer isolation
Customer data is queried within account/tenant scope; normal users cannot switch to another customer by changing account_id. Global administrator access is controlled separately.
Evidence: AccountAccess / tenant isolation feature testsIdentity and authorization
Customer and global administrator flows use separate authorization checks. Critical administration surfaces require global admin authorization.
Evidence: Controller authorization guardsSecret and payment data handling
Platform integration credentials are stored through encrypted model casts. Payment card PAN/CVV data is not stored in the application database and provider tokens are not rendered to customer UI.
Evidence: PlatformIntegration encrypted cast / billing security testsConsent and communication controls
Marketing consent, withdrawal evidence, suppression and IYS flows are managed with separate records and controls.
Evidence: Marketing consent and IYS models/testsOperations, audit and health visibility
Critical integration and billing flows expose health, audit and operational records. Sensitive secrets are not included in audit summaries.
Evidence: Integration health / billing operation audit
Scope note
This page does not claim certifications, a specific data location, guaranteed regulatory compliance or a standard SLA. Contractual and technical security details can be requested separately.
Owner: Product, Engineering & Legal · Last review: 2026-08-11 · Review by: 2026-10-11