Book a demo

Security and data · for the IT reviewer

Your network's data, in its own database, leaving only when you send it.

Almost every large customer now runs a security assessment before they sign, and the person running it doesn't want marketing copy. This page is what's on, described plainly. Where something is still being built, it says so. Where we don't have a certification, we don't claim one.

The network is the data controller. Brandfora is the processor.

hq.yourbrand.com/admin/security
Tenant · yourbrandIsolatedown database · own storage · own domain · own certificate
ControlStatusScope
MFA on admin surfacesOnevery admin login
Managed TLSActivehq.yourbrand.com + 1,214 store domains
Audit logAppend-onlyimpersonation logged
Card dataDelegated to Stripenever stored here
Supplier credentialsEncrypted at rest
SOC 2Readiness program underway
The admin security view. What you see is what's on.

Isolation

Per-tenant. Not rows in a shared table.

Each network runs on its own database, its own file storage, its own domain and its own certificate. Another network's data isn't a filter away from yours. It's in a different database. That's the answer most IT reviewers are looking for on the first page of the questionnaire, so it's the first thing here.

Every store under the network rides on that tenant. A custom domain on a store gets managed TLS: the certificate is issued and renewed by the system, and the store never serves without it.

Access

  • MFA on every admin surface
  • Sign-in by invite, email-domain gating or access code
  • Identity-provider sign-in on the roadmap
  • Roles scoped to HQ, location, store and buyer
  • Impersonation is possible for support, and every instance is written to the audit log

Data at rest and in transit

  • Supplier account credentials and API keys stored encrypted
  • Managed TLS on every custom domain, HQ and stores alike
  • Card data never touches our systems. Payment is delegated to Stripe on the location's own account
  • Append-only audit log: entries are written, never edited or removed

Who owns what

The network is the data controller. We are the processor.

The network's HQ decides what is collected, who sees it and how long it stays. We run the system on the network's behalf and act on the network's instructions. A location's customer list belongs to the location under the network's agreement, and HQ sees sales and fees, not that list, unless the agreement says otherwise. None of that is a setting we control. It's the structure.

Data leaves by API whenever the network wants it to. Orders leave by webhook to accounting and POS as they happen. There is no export request to file and no fee for leaving. We don't charge on your sales, so we have no reason to keep your data inside our walls.

Audit

Every change, who made it, and whether they were pretending to be someone else.

The audit log is append-only. Price changes, catalog pushes, user changes, permission changes, logins, and every support impersonation session are written with the actor, the time and the object. Nobody edits the log, including us. When a location asks who changed the price on its store, the answer is a row, not a guess.

1database per network
0card numbers stored by Brandfora
100%of impersonation sessions logged

Compliance

SOC 2 readiness program underway. In build

We are running a SOC 2 readiness program. That means controls are being documented and evidence collected against the framework. It does not mean we hold a SOC 2 report today, and we won't tell your reviewer otherwise. If your procurement process requires a completed report before signature, say so on the first call and we'll tell you where the program stands and what we can provide in the meantime: the architecture description, the control list, and access to our engineers for the review.

Questions reviewers ask

Is our data mixed with other customers' data?

No. Each network has its own database and its own storage. Isolation is per tenant, not per row.

Do you store card numbers?

No. Payment is delegated to Stripe, on the location's own Stripe account. Card data never reaches our systems.

How do users sign in?

Invite, email-domain gating or access code, depending on the store type and the network's rules. MFA is on for admin surfaces. Identity-provider sign-in is on the roadmap.

Can your staff see our data?

Support can impersonate a user to resolve an issue. Every impersonation session is written to the append-only audit log with who, when and what. The network can read that log.

Are you SOC 2 certified?

Not today. A SOC 2 readiness program is underway. We'll share where it stands on the call.

How do we get our data out?

By API, whenever you want it. Orders also leave by webhook as they happen. The network is the controller; we act on its instructions.

Who holds the TLS certificates for store domains?

The system issues and renews them. Every custom domain on the network, HQ and stores, serves under managed TLS.

Where are supplier credentials kept?

Encrypted at rest, per tenant. They're used to raise purchase orders on the location's own account and are never shared across networks.

Send us the questionnaire.

We'll answer it in writing, and put an engineer on the call with your reviewer.