Security & Trust
Enterprise-grade by design
Security and privacy are built into the platform, not bolted on. Below is how we protect customer data across identity, isolation, encryption, monitoring, and vendor management. For our subprocessor list and data-processing terms, see the legal pages.
Compliance posture
- SOC 2-grade control set: access reviews, data-retention policies, and change management.
- Right-to-erasure and evidence export for audits and data-subject requests.
- Signed DPA available, with EU Standard Contractual Clauses for international transfers.
Identity & access
- Federated single sign-on via OIDC and SAML 2.0.
- SCIM 2.0 for automated user provisioning and deprovisioning.
- Role- and actor-scoped authorization enforced on every request.
Tenant isolation
- Multi-tenant architecture with per-tenant data segregation enforced at the gateway.
- Every data path is scoped to the caller’s tenant — verified, not header-asserted.
- Per-tenant API keys with scoped permissions, rotation, and revocation.
Data protection
- Encryption in transit (TLS) and at rest.
- Secrets managed by reference, never stored in source.
- A Commerce360-managed AI model served by Google Cloud — no additional AI vendor.
Audit & monitoring
- Immutable audit trail across sensitive operations, with an admin review UI.
- Distributed tracing and metrics across the revenue path (OpenTelemetry).
- Signed outbound webhooks with delivery retries and a dead-letter queue.
Trust & anti-fraud
- Business verification (KYB) with sanctions/watchlist screening.
- Transaction fraud and risk scoring on checkout and payout.
- Dispute mediation with evidence threads and SLA timers.
Trust FAQ
- Do you support SSO and SCIM?
- Yes — federated OIDC and SAML 2.0 single sign-on, plus SCIM 2.0 for automated provisioning and deprovisioning.
- Where does the AI model run, and can we use our own?
- Today the AI Order Desk runs on a Commerce360-managed model: Google models on Vertex AI, served by Google Cloud under our agreement, with no additional AI vendor. The model is served from Google’s global endpoint, so we do not commit to a processing region for the AI model today. Conversation transcripts and audit records are stored by Commerce360. Bringing your own model — in your own cloud, or with your own provider key — and a dedicated self-hosted tier are planned and not yet available.
- How do you isolate tenants?
- The platform is multi-tenant with per-tenant data segregation enforced at the gateway; every data access is scoped to the authenticated tenant rather than trusting a client-supplied header.
- How do we report a vulnerability?
- Email our security team. We acknowledge reports promptly and work with reporters in good faith to validate and remediate.
Report a vulnerability
We work with security researchers in good faith. If you believe you've found a vulnerability, email our security team — we acknowledge reports promptly.