Security & data handling

Your catalog is confidential. We treat it that way.

We only list controls we actually operate. We do not claim certifications we do not hold, and we ask for less data than you might expect to share.

What we ask for, and what we don’t

The first audit needs a representative listing export. That is all.

  • No marketplace credentials. The snapshot and the founding sprint work from a CSV/XLSX export. We never ask for your Amazon or eBay login.
  • No pricing or margin data. You can strip prices, margins, and exact revenue from any file; priority tiers are enough.
  • No end-customer data. We do not want order data, consumer personal data, or payment data. Please leave it out of any export.
  • No full-catalog upload up front. Qualification happens first; a file is only requested from qualified applicants, capped at 250 representative rows.

How files are handled

  • Expiring upload links. Files are received through one-time, expiring secure links. Please do not send catalog files as email attachments.
  • Encryption. All traffic uses TLS; files at rest are stored with managed encryption.
  • Isolation. Each customer’s data is stored and processed separately. There is no cross-customer search over private documents, and private evidence is never reused for another customer without permission.
  • Limited human access. Access is restricted to the reviewers assigned to your engagement.

Retention and deletion

DataDefault handling
Raw uploaded filesDeleted 30 days after final delivery
Rejected or unqualified uploadsDeleted within 7 days
Delivered reportsRetained for the contract term plus any agreed period
Customer-private evidence documentsDeleted with raw data unless ongoing monitoring is contracted
Billing, contracts, audit eventsRetained according to legal and accounting obligations

Earlier deletion is available on request. Backup copies expire on a documented schedule rather than being surgically deleted, and we disclose that accurately rather than promising instant erasure.

AI providers and training

  • Customer data is processed only under enterprise or API terms that do not train models on customer input.
  • Customer documents are never pasted into consumer chat tools.
  • A subprocessor list (who processes what, where, and under which terms) is available on request and is included with the data-processing summary sent to qualified applicants.

Contracts

  • A data-processing summary is provided before any file is requested.
  • A Data Processing Agreement (DPA) is available for paid engagements.
  • An NDA is available on request before a sample is shared.

What we do not claim

We are an early-stage service and we say so. We do not currently claim SOC 2, ISO 27001, or independent penetration-test certification. We list only the controls above, and we will not invent badges to look bigger than we are. Questions about any control: [email protected].

Reporting a concern

If you believe data we hold is affected by a security issue, contact [email protected] with “SECURITY” in the subject line. Affected customers are notified in line with the DPA and applicable law.

Trust is earned with specifics

Read the methodology, open the sample report, then decide. Free snapshots are limited and fit-checked.

Get my free 250-row snapshot