Security

What protects your factory's data, stated plainly. We only list controls that exist today.

Last updated October 5, 2026

Where your data lives

  • Application: Vercel, Frankfurt region (fra1). Every request is served over HTTPS (TLS 1.2+).
  • Database: managed Postgres by Supabase, encrypted at rest. Supabase is a SOC 2 Type II audited provider; MRPverse itself has not completed its own SOC 2 audit and does not claim one.
  • Payments: Stripe. Card numbers never touch our servers; we store only the Stripe customer and subscription ids.

Tenant isolation

Every table carries a tenant id and is protected by Postgres row-level security. The database itself, not just the application code, refuses to return another business's rows.

Access and accounts

  • Passwords: at least 12 characters with upper-case, lower-case, number and symbol, stored as salted hashes.
  • Access log: every view or export of customer personal data is recorded with the user and time, visible to the owner under Settings → Security.
  • Integrations (Shopify, Etsy) use the minimum scopes; tokens are stored server-side and never sent to the browser.
  • MRPverse staff do not open customer accounts unless you ask for support, and every such access is logged.

Backups and recovery

Daily automated database backups are taken by Supabase. A nightly integrity job checks stock ledgers and order totals and alerts us on drift.

Your data is yours

Items, recipes, orders, customers and suppliers export in one click from Settings → Business at any time, in open CSV. Closing your account deletes your data after a 7-day safety window.

Incident response

A security incident is any event that may have exposed, altered or destroyed your data without authorisation.

  1. Contain within 1 hour of confirmation: revoke tokens, rotate secrets, block the path.
  2. Assess within 24 hours: which data, accounts and time window, from database, hosting and access logs.
  3. Notify within 72 hours: affected customers by email with what happened and what to do; platform partners and authorities where required.
  4. Recover and review: fix the root cause, then publish a post-incident report within 2 weeks.

Reporting a vulnerability

Email security@mrpverse.com with details. We acknowledge within 2 business days and never take action against good-faith research.