Trust & security

Privacy architecture

One principle — the least data necessary for each job — delivered by a different mechanism in each product. This page is what our contracts reference; every claim on it maps to shipped, inspectable code.

ProductMechanismThe promise
Audit & OriginClient-side tokenizationWe only ever see the anonymized shape of your BOM
Scope 3 agentSelf-hosted, zero dependenciesYour supplier data never leaves your infrastructure
ComplianceData minimization + encryptionWe hold only what the task requires; identified data is named and contracted

Audit & Origin — "shape, not secrets"

Try the ingestion gate

This is the Studio's intake gate, running in your browser. Type a supplier name such as Acme Plastics into a supplier cell, or an email or phone number into a notes cell, and it is rejected with the gate's own message. A token such as SUP-c109b709 passes. Nothing you type is sent anywhere. The only request this page makes after it loads is one cookieless pageview count carrying the page path, with no referrer, screen size, clicks or timings; the gate itself makes none. You can confirm both in your browser's network inspector.

stream_labelsupplierpart_numbernotes

Pattern-based checks, the same ones the Studio applies before any upload. Not legal, regulatory or investment advice.

Scope 3 agent — nothing leaves at all

Compliance — the least identified data the job allows

Honesty notes (read these too)