Your catalog is confidential. We treat it that way.
We only list controls we actually operate. We do not claim certifications we do not hold, and we ask for less data than you might expect to share.
What we ask for, and what we don’t
The first audit needs a representative listing export. That is all.
- No marketplace credentials. The snapshot and the founding sprint work from a CSV/XLSX export. We never ask for your Amazon or eBay login.
- No pricing or margin data. You can strip prices, margins, and exact revenue from any file; priority tiers are enough.
- No end-customer data. We do not want order data, consumer personal data, or payment data. Please leave it out of any export.
- No full-catalog upload up front. Qualification happens first; a file is only requested from qualified applicants, capped at 250 representative rows.
How files are handled
- Expiring upload links. Files are received through one-time, expiring secure links. Please do not send catalog files as email attachments.
- Encryption. All traffic uses TLS; files at rest are stored with managed encryption.
- Isolation. Each customer’s data is stored and processed separately. There is no cross-customer search over private documents, and private evidence is never reused for another customer without permission.
- Limited human access. Access is restricted to the reviewers assigned to your engagement.
Retention and deletion
| Data | Default handling |
|---|---|
| Raw uploaded files | Deleted 30 days after final delivery |
| Rejected or unqualified uploads | Deleted within 7 days |
| Delivered reports | Retained for the contract term plus any agreed period |
| Customer-private evidence documents | Deleted with raw data unless ongoing monitoring is contracted |
| Billing, contracts, audit events | Retained according to legal and accounting obligations |
Earlier deletion is available on request. Backup copies expire on a documented schedule rather than being surgically deleted, and we disclose that accurately rather than promising instant erasure.
AI providers and training
- Customer data is processed only under enterprise or API terms that do not train models on customer input.
- Customer documents are never pasted into consumer chat tools.
- A subprocessor list (who processes what, where, and under which terms) is available on request and is included with the data-processing summary sent to qualified applicants.
Contracts
- A data-processing summary is provided before any file is requested.
- A Data Processing Agreement (DPA) is available for paid engagements.
- An NDA is available on request before a sample is shared.
What we do not claim
We are an early-stage service and we say so. We do not currently claim SOC 2, ISO 27001, or independent penetration-test certification. We list only the controls above, and we will not invent badges to look bigger than we are. Questions about any control: [email protected].
Reporting a concern
If you believe data we hold is affected by a security issue, contact [email protected] with “SECURITY” in the subject line. Affected customers are notified in line with the DPA and applicable law.
Trust is earned with specifics
Read the methodology, open the sample report, then decide. Free snapshots are limited and fit-checked.
Get my free 250-row snapshot