Skip to main content

Security

Tenant isolation and audit history

We publish the controls we can evidence on this page—nothing more.

Layered tenant isolation

Authenticated workspace context scopes every customer-data path, with database policies adding fail-closed enforcement to customer-facing records. PostgreSQL row-level security protects the public application schema; platform and canonical paths retain explicit tenant-scoped authorization.

Authorization and human review

Sensitive inventory and financial mutations require authorized actors. AI and document parsers create drafts only—humans review before posting.

Audit history

Security-relevant actions record actor, action, time, and outcome—including login activity—so corrections and access remain accountable.

Encryption in transit and at rest

Application traffic uses TLS in transit. Data at rest uses AES-256 encryption for database storage and backups (Aurora storage encryption with AWS KMS).

Assurance scope

Bazaroo does not claim SOC 2, ISO, PCI, GDPR, or other certifications it has not completed. This page describes only the controls we can evidence today.

Responsible disclosure

If you find a security issue, report it responsibly to [email protected]

Questions about security posture?

Contact us for materials not published on this page, or book a migration review to discuss operating boundaries.