Security and data · for the IT reviewer
Your network's data, in its own database, leaving only when you send it.
Almost every large customer now runs a security assessment before they sign, and the person running it doesn't want marketing copy. This page is what's on, described plainly. Where something is still being built, it says so. Where we don't have a certification, we don't claim one.
The network is the data controller. Brandfora is the processor.
| Control | Status | Scope |
|---|---|---|
| MFA on admin surfaces | On | every admin login |
| Managed TLS | Active | hq.yourbrand.com + 1,214 store domains |
| Audit log | Append-only | impersonation logged |
| Card data | Delegated to Stripe | never stored here |
Isolation
Per-tenant. Not rows in a shared table.
Each network runs on its own database, its own file storage, its own domain and its own certificate. Another network's data isn't a filter away from yours. It's in a different database. That's the answer most IT reviewers are looking for on the first page of the questionnaire, so it's the first thing here.
Every store under the network rides on that tenant. A custom domain on a store gets managed TLS: the certificate is issued and renewed by the system, and the store never serves without it.
Access
- MFA on every admin surface
- Sign-in by invite, email-domain gating or access code
- Identity-provider sign-in on the roadmap
- Roles scoped to HQ, location, store and buyer
- Impersonation is possible for support, and every instance is written to the audit log
Data at rest and in transit
- Supplier account credentials and API keys stored encrypted
- Managed TLS on every custom domain, HQ and stores alike
- Card data never touches our systems. Payment is delegated to Stripe on the location's own account
- Append-only audit log: entries are written, never edited or removed
Who owns what
The network is the data controller. We are the processor.
The network's HQ decides what is collected, who sees it and how long it stays. We run the system on the network's behalf and act on the network's instructions. A location's customer list belongs to the location under the network's agreement, and HQ sees sales and fees, not that list, unless the agreement says otherwise. None of that is a setting we control. It's the structure.
Data leaves by API whenever the network wants it to. Orders leave by webhook to accounting and POS as they happen. There is no export request to file and no fee for leaving. We don't charge on your sales, so we have no reason to keep your data inside our walls.
Audit
Every change, who made it, and whether they were pretending to be someone else.
The audit log is append-only. Price changes, catalog pushes, user changes, permission changes, logins, and every support impersonation session are written with the actor, the time and the object. Nobody edits the log, including us. When a location asks who changed the price on its store, the answer is a row, not a guess.
Compliance
SOC 2 readiness program underway. In build
We are running a SOC 2 readiness program. That means controls are being documented and evidence collected against the framework. It does not mean we hold a SOC 2 report today, and we won't tell your reviewer otherwise. If your procurement process requires a completed report before signature, say so on the first call and we'll tell you where the program stands and what we can provide in the meantime: the architecture description, the control list, and access to our engineers for the review.
Questions reviewers ask
Is our data mixed with other customers' data?
No. Each network has its own database and its own storage. Isolation is per tenant, not per row.
Do you store card numbers?
No. Payment is delegated to Stripe, on the location's own Stripe account. Card data never reaches our systems.
How do users sign in?
Invite, email-domain gating or access code, depending on the store type and the network's rules. MFA is on for admin surfaces. Identity-provider sign-in is on the roadmap.
Can your staff see our data?
Support can impersonate a user to resolve an issue. Every impersonation session is written to the append-only audit log with who, when and what. The network can read that log.
Are you SOC 2 certified?
Not today. A SOC 2 readiness program is underway. We'll share where it stands on the call.
How do we get our data out?
By API, whenever you want it. Orders also leave by webhook as they happen. The network is the controller; we act on its instructions.
Who holds the TLS certificates for store domains?
The system issues and renews them. Every custom domain on the network, HQ and stores, serves under managed TLS.
Where are supplier credentials kept?
Encrypted at rest, per tenant. They're used to raise purchase orders on the location's own account and are never shared across networks.
Send us the questionnaire.
We'll answer it in writing, and put an engineer on the call with your reviewer.