Trust center

Security controls mapped to the decisions they protect.

Review identity, tenant, role, site, integration, device, audit, and recovery controls together with the deployment responsibilities around them.

Security and procurement

Current controls and deployment documentation.

Review product controls together with your architecture, hosting, contractual, and data-protection requirements.

Identity, role, action, and session controls

Product mechanisms and authorization policy are available for technical review.

Implemented

Tenant isolation and audited data access

Application tenant scope and database row-level policies enforce access to client-owned records.

Implemented

Current production hosting

Amazon Web Services EMEA SARL, AWS Europe (Stockholm), eu-north-1. Customer-specific residency and environment topology remain contractual.

Configured

Backup, restore, and disaster recovery

Checksum/compressed SQL backup tooling, restore verification, backup-freshness health, and a tiered RTO/RPO runbook exist. Activation and drill evidence are verified per deployment.

Deployment evidence

Incident management

Operational cases, immutable audit, health state, recovery playbooks, and security-event evidence support response. Notification ownership and contractual response targets remain organization-specific.

Implemented controls

Data Processing Agreement and subprocessor schedule

Processing roles, transfer safeguards, retention, subprocessors, and contractual controls are defined during contracting.

Contracting document

Independent certifications and audit reports

No current SOC 2 or ISO 27001 attestation is included with the platform.

No current attestation

Defence in depth

Apply controls where the decision is made.

Product controls cover identity, tenancy, authorization, and audit. Deployment review adds environment topology, residency, service levels, and organizational controls.

IDENTITY

Session and authentication

Backend-managed refresh continuity, memory-only access tokens, SSO/2FA paths, and session controls.

TENANT

Row-level isolation

Tenant filters and database row-level policies protect client-scoped operational and commercial data.

ACTION

Role and capability checks

Routes and mutations evaluate role, tenant, warehouse, module, feature, and backend support before execution.

EVIDENCE

Audit and immutable records

Operational changes, events, labels, financial ledgers, and security activity retain traceable evidence.

Multi-client isolation

Client scope is enforced below the page.

UI filtering is not the security boundary. Application tenant context and database row-level controls constrain inventory, orders, plans, finance, users, and related records.

DATABASE

Row-level policies

Entity coverage and partner/client predicates are governed and tested against expected ownership models.

APPLICATION

Scoped queries and commands

Handlers require the tenant and authorization context appropriate to the business operation.

SUPPORT

Controlled assistance

Support and impersonation paths stay explicit, audited, and constrained rather than reusing browser-stored secrets.

Integration security

Credentials and machine identity stay purpose-scoped.

API KEYS

Explicit scopes

Machine keys carry allowed scopes and tenant binding rather than inheriting a generic interactive-user identity.

WEBHOOKS

Signing and replay control

Signing secrets, verification, event identity, timestamps, and idempotency protect inbound event processing.

PAYMENTS

Sensitive-data boundaries

Provider signatures, durable inboxes, redacted logging, immutable ledgers, and explicit reconciliation reduce money-path ambiguity.

Floor and device boundary

Warehouse hardware connects to warehouse devices.

Printers, scanners, cameras, and station hardware remain behind a local mobile or desktop bridge. Business services create governed jobs and artifacts; they do not open direct connections to floor devices.

  • Backend APIs own business intent and authorization.
  • Warehouse stations and handhelds own local hardware transport.
  • Acknowledgement, failure, and retry state return as operational evidence.
XMS Cloud desktop floor station with local hardware bridge
Operator session, work queue, validation, local devices, and offline continuity.

Resilience

Degraded operation is a designed state.

Offline queues, idempotent replay, event outboxes, retries, reconciliation, health checks, and fail-closed configuration guards make recovery observable.

OFFLINE

Continue and reconcile

Frontline operations retain durable local work and submit scoped batches when connectivity returns.

REPLAY

Idempotent recovery

Correlation and idempotency keys prevent ordinary retries from silently duplicating business actions.

STARTUP

Fail closed

Production configuration guards stop known unsafe payment, security, and infrastructure states at startup.

Security validation scenarios

Exercise denial, replay, revocation, and data export.

Use scoped identifiers, a registered device, duplicate events, and an exported archive to validate the deployed controls.

Cross-tenant identifiers

Use a valid client A session against client B inventory, order, quote, wallet, and takeout identifiers. Require denial at application and database scope.

Revoked floor device

Submit offline work from a lost or revoked device, wrong operator, wrong warehouse, and mismatched source type. Verify every event is rejected.

Duplicate and sequence handling

Replay one event, reuse its id under another user, skip a local sequence, exceed age and payload bounds, and inspect per-event results.

Verifiable tenant takeout

Generate the contracted dataset archive, validate schema versions, row counts and SHA-256 hashes, then audit the download.

Security review

Bring your tenancy, identity, integration, and device model.

Review the exact deployment assumptions, data paths, roles, controls, evidence, recovery, and open compliance requirements.