Security
What protects your factory's data, stated plainly. We only list controls that exist today.
Last updated October 5, 2026
Where your data lives
- Application: Vercel, Frankfurt region (fra1). Every request is served over HTTPS (TLS 1.2+).
- Database: managed Postgres by Supabase, encrypted at rest. Supabase is a SOC 2 Type II audited provider; MRPverse itself has not completed its own SOC 2 audit and does not claim one.
- Payments: Stripe. Card numbers never touch our servers; we store only the Stripe customer and subscription ids.
Tenant isolation
Every table carries a tenant id and is protected by Postgres row-level security. The database itself, not just the application code, refuses to return another business's rows.
Access and accounts
- Passwords: at least 12 characters with upper-case, lower-case, number and symbol, stored as salted hashes.
- Access log: every view or export of customer personal data is recorded with the user and time, visible to the owner under Settings → Security.
- Integrations (Shopify, Etsy) use the minimum scopes; tokens are stored server-side and never sent to the browser.
- MRPverse staff do not open customer accounts unless you ask for support, and every such access is logged.
Backups and recovery
Daily automated database backups are taken by Supabase. A nightly integrity job checks stock ledgers and order totals and alerts us on drift.
Your data is yours
Items, recipes, orders, customers and suppliers export in one click from Settings → Business at any time, in open CSV. Closing your account deletes your data after a 7-day safety window.
Incident response
A security incident is any event that may have exposed, altered or destroyed your data without authorisation.
- Contain within 1 hour of confirmation: revoke tokens, rotate secrets, block the path.
- Assess within 24 hours: which data, accounts and time window, from database, hosting and access logs.
- Notify within 72 hours: affected customers by email with what happened and what to do; platform partners and authorities where required.
- Recover and review: fix the root cause, then publish a post-incident report within 2 weeks.
Reporting a vulnerability
Email security@mrpverse.com with details. We acknowledge within 2 business days and never take action against good-faith research.