Platform security

Who can act, on which records?

For teams serving multiple clients: separate warehouse work, manager decisions and account administration. Agree expected access denials and export coverage during setup.

Identity

Define responsibilities before granting access

Users and organisations

Identify the client account, partner, warehouses and required roles. Access to a module does not by itself grant access to another client.

System access

For a technical connection, define its identity and scope. A delegated assistant session also carries the user context.

Access control

Signing in does not authorise every action: VAS planning and verification, for example, require manager authority.

Product entitlement

Example: approve a VAS operation

  1. Role

    The operator submits the work. The verification decision requires a manager or another authorised higher role.

  2. Work status

    The record must be in the authorised scope and pending verification. A manager role does not replace that state requirement.

Scope

Check the access that should be denied, too

Cases to check

  • a client administrator requests another client’s export
  • an operator attempts verification reserved for a manager
  • an action targets a warehouse outside the user’s scope

Controls to review

  • access policies on the API and requested action
  • record filtering for the relevant client and warehouse
  • SQL Server isolation policies on covered tables, to verify in the deployment

History and review

Find the events linked to the work

Audit trail

VAS transitions record the work order and its status change. Verification retains the decision and notes.

Security audit

Security screens let authorised roles review login attempts and the audit records available to them.

Health and administration

Define who administers the account and follows up requests. Assistant ticket creation and export or download requests produce audit events.

Reversibility

Export nine defined datasets

Export contents, permission and result

The export covers products, customers, orders, order lines, stock, inventory ledger, configuration instances, configuration overrides and audit events. This is not a copy of every dataset in the platform.

An authorised client administrator exports their own account; platform administration has broader access. Processing is asynchronous: an active job for the same client blocks another request, and download waits for completion.

The completed ZIP contains NDJSON files, plus CSV for products and customers. Its manifest records schema versions, row counts and SHA-256 hashes; job status also exposes failures.

What this ZIP does not cover

Shipments, invoices, proof-of-delivery documents, photos and packing videos are not datasets in this standard export. A reference in an order or audit event does not mean the associated document is included.

If you also need these records, separately confirm which data and documents can be supplied, their format and how they will be delivered. Do not treat this export as a complete backup.

Agree your exit scope

  • List the datasets and documents you need, including any accepted exclusions.
  • Identify the account and the people authorized to request and receive the files.
  • Agree receipt checks: expected files, row counts and SHA-256 verification.
  • Confirm the delivery schedule, availability period and applicable retention or deletion arrangements.

Supplier information

The company, service scope and practical terms for your procurement review.

Provider and service

The Software Terms name YSEND, trading as YSEND GROUP, a French SAS registered under SIREN 843 222 746, as the provider. Your Order Form defines the modules, sites, users, implementation and support included.

Hosting and data

This website is hosted in AWS Europe (Stockholm). For your service, confirm data locations, subprocessors and retention arrangements. Where personal data is processed on your behalf, the applicable Data Processing Agreement governs.

Access and integrations

You manage authorised users, roles and credentials. Define the scope of technical connections during setup. Your organisation remains responsible for its source data and the integrations it controls.

Support and continuity

The support level and any availability, response-time or recovery commitments are set out in your Order Form or SLA. Confirm the support channels, incident notifications and backup/restoration arrangements that apply to your deployment.

Export and exit

The standard export covers the nine datasets detailed above: ZIP with NDJSON, plus CSV for products and customers. Separately confirm availability of shipments, invoices, proof-of-delivery documents and media. Agree any assistance, charges, delivery and deletion arrangements for your service.

Specify the company and services involved, the documents you need and your decision timeline. Agree the document scope and delivery arrangements with our team.

Request documents for my project

Updated