Draft — not yet in force. This document has not been reviewed by counsel, and the highlighted markers below are unresolved. It is excluded from search indexing until both are addressed.
Security at Suppli
The controls behind a product that connects to your ERP, holds your customers' details, and moves your money.
Last updated [ TO CONFIRM: effective date ]
Our approach
Suppli sits between a distributor’s ERP and their customers, and it moves money. That puts three things in our care at once: the ledger a business runs on, the contact details of their customers, and payment instruments. We build and operate the product on that basis.
This page describes the controls we maintain. If you are completing a vendor review, write to [ TO CONFIRM: security contact email ] and we will share our current report and answer a questionnaire.
Certifications and audits
| Programme | Status |
|---|---|
| SOC 2 | Certified. [ TO CONFIRM: confirm Type I or Type II, the trust services criteria in scope, the audit period, and the auditor ] |
| PCI DSS | Compliant. [ TO CONFIRM: confirm the level and validation route — most SaaS that never touches a PAN validates as SAQ-A through its processor ] |
| Penetration testing | [ TO CONFIRM: confirm cadence and whether a summary letter is available under NDA ] |
Reports are available to customers and qualified prospects under NDA. Request them at [ TO CONFIRM: security contact email ].
Protecting data
In transit and at rest
All traffic to Suppli is encrypted in transit using TLS. Data at rest is encrypted using [ TO CONFIRM: encryption standard and key management approach ].
Payment instruments
Card and bank details are captured and vaulted by our payment processor, [ TO CONFIRM: payment processor name ]. Suppli stores a token and the transaction record. Full payment instrument numbers do not enter or persist in our systems.
Tenant separation
[ TO CONFIRM: describe the isolation model — logical separation with tenant scoping, or separate databases per customer. InfoSec reviewers ask this early ]
Infrastructure
Suppli runs on [ TO CONFIRM: cloud provider ] in [ TO CONFIRM: region(s) ]. We inherit that provider’s physical and environmental controls and their own audit programme.
- Environments are separated, and production data is not used in development or testing.
- Infrastructure changes are version-controlled and peer-reviewed.
- Systems and dependencies are patched on [ TO CONFIRM: patching cadence and severity-based SLA ].
- Logging and monitoring: [ TO CONFIRM: tooling and alerting model ]
Access control
- Access follows least privilege and is granted by role, not by person.
- Employee access requires SSO with multi-factor authentication, and is reviewed [ TO CONFIRM: review cadence ].
- Access is revoked as part of offboarding, on [ TO CONFIRM: revocation SLA ].
- Production access is limited to staff who need it, and is logged. [ TO CONFIRM: confirm whether it is break-glass or standing access ]
- For customers: [ TO CONFIRM: confirm what the application offers — SSO/SAML, SCIM, role-based permissions, audit log export ]
Secure development
- Changes are peer-reviewed before merge and deployed through an automated pipeline.
- Dependencies are scanned for known vulnerabilities, and static analysis runs in CI. [ TO CONFIRM: confirm tooling ]
- Engineers receive secure development training [ TO CONFIRM: frequency ], and all staff complete security awareness training at hire and annually.
- Background checks are performed where law permits. [ TO CONFIRM: confirm scope ]
Availability and resilience
- Backups: [ TO CONFIRM: frequency, retention, and how often restores are tested ]
- Recovery objectives: [ TO CONFIRM: RTO and RPO ]
- Uptime commitment: [ TO CONFIRM: SLA, if one is offered, and whether a status page exists ]
Because Suppli syncs bi-directionally with a customer’s ERP, that ERP remains the system of record. A Suppli outage does not put a customer’s ledger out of reach.
Incident response
We maintain a documented incident response plan covering detection, triage, containment, eradication, recovery, and post-incident review, and we exercise it [ TO CONFIRM: exercise cadence ].
If an incident affects a customer’s data, we will notify them without undue delay and within [ TO CONFIRM: notification window, and check it against the DPA and applicable breach-notification law ], with the facts known at the time and updates as the investigation proceeds.
Sub-processors
We use a small set of vendors to run infrastructure, payments, and communications. Each is assessed before use and bound by contract. The current list is at [ TO CONFIRM: sub-processor list URL, or state that it is available on request ], and customers can subscribe to notice of changes.
Reporting a vulnerability
If you believe you have found a security issue in Suppli, tell us at [ TO CONFIRM: security contact email ]. Please include enough detail to reproduce it, and give us a reasonable opportunity to fix it before disclosing publicly.
We will acknowledge your report within [ TO CONFIRM: acknowledgement window ]. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and do not access or modify data that is not their own.
[ TO CONFIRM: decide whether to publish a security.txt at /.well-known/security.txt and whether a bug bounty is offered ]