Skip to content
Security

Security backed by verifiable controls

The security of your company's data is our priority. We distinguish implemented controls from operational requirements that must be verified before production is enabled.

SSL/TLS encryption

Traffic between your browser and the service uses HTTPS/TLS. Payment and CSD secrets remain outside the browser and are excluded from logs and prompts.

Secure infrastructure

Operational data uses managed PostgreSQL. Before enabling production, we verify the contracted provider's encryption, access, region, and recovery configuration.

Verified recovery

Production activation requires a documented backup/PITR policy and a timed restore drill. The applicable RPO, RTO, and retention are documented per environment.

Secure authentication

Authentication uses signed Supabase sessions. Staff can enroll TOTP, and privileged Commerce APIs require an AAL2 session when the environment is production.

Access control

Permissions are assigned by role and audience. APIs validate the session, active workspace, and permissions before accepting each operation.

Data isolation

RLS, tenant-scoped repositories, and explicit-context RPCs isolate clients. Adversarial tests cover foreign IDs, audiences, and service-role queries.

Audits and monitoring

Audit, outbox, reconciliation, and worker-health signals support operations. Dashboards, alerts, and notification procedures are release requirements and follow applicable law and contract.

Regulatory compliance

CI checks dependencies, secrets, permissions, and route boundaries. An independent penetration test plus legal and fiscal review are mandatory before general availability.

Found a vulnerability?

If you discover a security issue, we ask that you report it responsibly before making it public. Our team will address it as a priority.

admin@vorta.mx