Identity
Confirmed email required
Buyer and supplier private actions require an authenticated, email-confirmed account or a scoped invite.
Buyer security review
An implementation-level summary of the controls protecting buyer workspaces, supplier evidence, connector credentials, and billing boundaries in the current XveriTrade service.
Last reviewed: August 10, 2026
Identity
Buyer and supplier private actions require an authenticated, email-confirmed account or a scoped invite.
Workspace records
Policies, evidence reviews, decisions, and audit reads are constrained to the owning buyer relationship.
Connector credentials
Provider tokens are encrypted with AES-256-GCM before database storage and are never rendered publicly.
Payment details
Stripe collects card and billing details. XveriTrade does not receive or store full card numbers or security codes.
Implemented controls
The public supplier signal surface stays separate from private buyer evidence, decisions, audit records, and connector credentials.
01
02
03
04
Service roles
These providers support the live service. Product-specific data residency, contractual, or subprocessor requirements should be confirmed during a buyer review rather than inferred from this list.
Current assurance boundary
XveriTrade does not currently claim SOC 2 or ISO 27001 certification or an independent penetration-test attestation. It also does not independently authenticate supplier-submitted documents.
A buyer that requires a DPA, security questionnaire, specific data residency, contractual security terms, or external assurance should raise that requirement before pilot acceptance. No certification, location, or contractual commitment is assumed until confirmed in writing.
Procurement-ready questions
Use the 30-day guided pilot to test one buyer-owned approval process. Bring any security requirement that could affect pilot scope before activation.