Security backed by verifiable controls
The security of your company's data is our priority. We distinguish implemented controls from operational requirements that must be verified before production is enabled.
SSL/TLS encryption
Traffic between your browser and the service uses HTTPS/TLS. Payment and CSD secrets remain outside the browser and are excluded from logs and prompts.
Secure infrastructure
Operational data uses managed PostgreSQL. Before enabling production, we verify the contracted provider's encryption, access, region, and recovery configuration.
Verified recovery
Production activation requires a documented backup/PITR policy and a timed restore drill. The applicable RPO, RTO, and retention are documented per environment.
Secure authentication
Authentication uses signed Supabase sessions. Staff can enroll TOTP, and privileged Commerce APIs require an AAL2 session when the environment is production.
Access control
Permissions are assigned by role and audience. APIs validate the session, active workspace, and permissions before accepting each operation.
Data isolation
RLS, tenant-scoped repositories, and explicit-context RPCs isolate clients. Adversarial tests cover foreign IDs, audiences, and service-role queries.
Audits and monitoring
Audit, outbox, reconciliation, and worker-health signals support operations. Dashboards, alerts, and notification procedures are release requirements and follow applicable law and contract.
Regulatory compliance
CI checks dependencies, secrets, permissions, and route boundaries. An independent penetration test plus legal and fiscal review are mandatory before general availability.
Found a vulnerability?
If you discover a security issue, we ask that you report it responsibly before making it public. Our team will address it as a priority.
admin@vorta.mx