Identity, role, action, and session controls
Product mechanisms and authorization policy are available for technical review.
Trust center
Review identity, tenant, role, site, integration, device, audit, and recovery controls together with the deployment responsibilities around them.
Security and procurement
Review product controls together with your architecture, hosting, contractual, and data-protection requirements.
Product mechanisms and authorization policy are available for technical review.
Application tenant scope and database row-level policies enforce access to client-owned records.
Amazon Web Services EMEA SARL, AWS Europe (Stockholm), eu-north-1. Customer-specific residency and environment topology remain contractual.
Checksum/compressed SQL backup tooling, restore verification, backup-freshness health, and a tiered RTO/RPO runbook exist. Activation and drill evidence are verified per deployment.
Operational cases, immutable audit, health state, recovery playbooks, and security-event evidence support response. Notification ownership and contractual response targets remain organization-specific.
Processing roles, transfer safeguards, retention, subprocessors, and contractual controls are defined during contracting.
No current SOC 2 or ISO 27001 attestation is included with the platform.
Report security issues or request the vulnerability-handling process at contact@ysendgroup.com.
Defence in depth
Product controls cover identity, tenancy, authorization, and audit. Deployment review adds environment topology, residency, service levels, and organizational controls.
Backend-managed refresh continuity, memory-only access tokens, SSO/2FA paths, and session controls.
Tenant filters and database row-level policies protect client-scoped operational and commercial data.
Routes and mutations evaluate role, tenant, warehouse, module, feature, and backend support before execution.
Operational changes, events, labels, financial ledgers, and security activity retain traceable evidence.
Multi-client isolation
UI filtering is not the security boundary. Application tenant context and database row-level controls constrain inventory, orders, plans, finance, users, and related records.
Entity coverage and partner/client predicates are governed and tested against expected ownership models.
Handlers require the tenant and authorization context appropriate to the business operation.
Support and impersonation paths stay explicit, audited, and constrained rather than reusing browser-stored secrets.
Integration security
Machine keys carry allowed scopes and tenant binding rather than inheriting a generic interactive-user identity.
Signing secrets, verification, event identity, timestamps, and idempotency protect inbound event processing.
Provider signatures, durable inboxes, redacted logging, immutable ledgers, and explicit reconciliation reduce money-path ambiguity.
Floor and device boundary
Printers, scanners, cameras, and station hardware remain behind a local mobile or desktop bridge. Business services create governed jobs and artifacts; they do not open direct connections to floor devices.

Resilience
Offline queues, idempotent replay, event outboxes, retries, reconciliation, health checks, and fail-closed configuration guards make recovery observable.
Frontline operations retain durable local work and submit scoped batches when connectivity returns.
Correlation and idempotency keys prevent ordinary retries from silently duplicating business actions.
Production configuration guards stop known unsafe payment, security, and infrastructure states at startup.
Security validation scenarios
Use scoped identifiers, a registered device, duplicate events, and an exported archive to validate the deployed controls.
Use a valid client A session against client B inventory, order, quote, wallet, and takeout identifiers. Require denial at application and database scope.
Submit offline work from a lost or revoked device, wrong operator, wrong warehouse, and mismatched source type. Verify every event is rejected.
Replay one event, reuse its id under another user, skip a local sequence, exceed age and payload bounds, and inspect per-event results.
Generate the contracted dataset archive, validate schema versions, row counts and SHA-256 hashes, then audit the download.
Security review
Review the exact deployment assumptions, data paths, roles, controls, evidence, recovery, and open compliance requirements.