Security · Trust

Enterprise security & trust. Your data, your control.

Built for B2B SaaS standards from day one, tenant isolation, audit trails, and a recommend-only default that means nothing reaches your store without your explicit approval.

Trust

Security you can verify, not just read about.

Database-enforced isolation, encrypted credentials, and a recommend-only default, every claim on this page maps to a shipped control.

Tenant isolation

Every merchant query runs inside a tenant-scoped context, backed by forced row-level-security policies on every merchant-scoped table and an automated drift check in CI on every change.

Encrypted credentials

Store credentials are encrypted at rest, decrypted only for sync operations, and never leave our infrastructure. TLS in transit everywhere.

Recommend-only default

Zero silent automations. Nothing is written to your store without your explicit approval, and every applied change is reversible and logged.

Full audit trail

Approvals, rejections, rollbacks, configuration changes, and team actions are recorded with actor and timestamp, for the life of your account.

Principles

How we treat your data.

Six commitments we hold ourselves to, in production today.

Tenant isolation

Every merchant query runs inside a tenant-scoped context. Row-level security is forced on every merchant-scoped table, with an automated drift check in CI so isolation policy never silently regresses.

Credential handling

Store credentials are encrypted at rest. They are decrypted only for sync operations and never leave our infrastructure.

Data minimization

We fetch what the features you use require: catalog and pricing fields, and order records where they power your outcome reporting. Merchant data is never sold or shared, and it powers only your own account.

Recommend-only by default

No connected store has anything written to it without your explicit approval. Hard guardrails on margin, price floor, and change velocity check every recommendation before it reaches you, and any autonomy beyond that is yours to unlock, never a default.

Audit log

Every action, approval, rejection, undo, configuration change, team invite, is recorded with actor and timestamp. The audit log is retained for the life of your account.

Right to delete

Cancel and your data is retained for 30 days for reactivation. Export your data at any time, and file a deletion request from your account, both run through the privacy tools built into the product.

Compliance

Where we stand on compliance.

What we align with today. We hold no third-party certifications yet and won’t claim one before it exists.

Active

GDPR-aligned practices

Our data-handling practices follow UK and EU GDPR principles: data minimization, deletion requests, and export on request. Data Processing Addendum available on request.

Active

Regional data-protection laws

Aligned with GDPR-style data-protection regimes worldwide. Support for regional laws, including Saudi PDPL, available on request.

Practices

What’s in production today.

Concrete details, not marketing language. If you need an item that isn’t listed here, ask, we’d rather tell you the truth than oversell.

HostingManaged cloud infrastructure · TLS in transit · encrypted credential storage · data-residency options on request
AuthenticationEmail/password sign-in with HttpOnly signed cookies · no third-party OAuth
AuthorizationRole-based access control (owner, admin, analyst, viewer) with granular permissions
Rate limitingTiered rate limiting across mutations, queries, auth, and webhooks
Input validationSchema validation on every write, with field-level error reporting
LoggingStructured logs with request correlation and no credential leakage
BackupsRegular database snapshots with a documented restore procedure · off-site backup automation in progress
UpdatesVersioned releases · transaction-safe schema migrations

Procurement & security review

Need a DPA, a security questionnaire, or detail on any control?

Email support@melqart.me. We respond within one business day.