Security
What actually protects your data, described specifically enough that you can hold us to it.
On this page 9 sections
What we do and don't claim
Plainly, so you can plan around it: Magemcy does not currently hold SOC 2, ISO 27001, HIPAA, PCI DSS or FedRAMP certification, and has not completed a third-party audit or penetration test. If your procurement process requires one of those, we would rather you knew now than discovered it three weeks into a review.
There is also no such thing as being “GDPR certified”, no scheme exists to certify it, so nobody can honestly claim that, us included. What we can do is describe the controls that are actually in place. That is the rest of this page.
Card data is a specific exception worth naming: because payments are handled entirely by Stripe’s hosted checkout, card details never reach our servers at all, and our exposure to PCI scope is limited accordingly.
Tenant isolation
Every company’s workspace is separated from every other one, and that separation is enforced by database security rules on the server, not by the application deciding what to show you. The distinction matters: a bug in the interface, or a modified client, still cannot read another company’s data, because the database refuses the read regardless of what asked for it.
The same applies inside a workspace. Roles are enforced at the same layer, so a viewer cannot write by calling the API directly.
On two-envelope tenders, commercial figures are stored in a separate protected record that is unreadable until authorised openers reveal it. Sealed means sealed for the buyer too.
Encryption
All traffic is over TLS. Data at rest is encrypted by our infrastructure provider (Google Cloud), including database contents and uploaded files. Uploads are restricted by type and size, and file formats that could execute in a browser are rejected rather than merely discouraged.
Authentication and access
Sign-in is by email and password or by Google, handled by Google Firebase Authentication. We never see or store your password. An email address must be verified before a workspace can be created or joined, and sessions are checked for revocation on every privileged server call, so signing out, or being removed, takes effect immediately rather than at the next token expiry.
Payments
Subscriptions run through Stripe’s hosted checkout and billing portal. Card details go directly from your browser to Stripe; they never touch Magemcy. Plan status is written only by Stripe’s signature-verified webhook, so no client can grant itself a paid plan by manipulating a request.
Email approval tokens
One-click approval links let an approver sign off a purchase order from their inbox, which means a link in an email carries real authority. So each one is a 256-bit random token, stored hashed rather than in the clear, single-use, expiring, and bound to one specific approver, document and approval level. The link itself only opens a confirmation page; approving requires the click.
AI processing
AI requests go to Google’s Gemini API, or to OpenAI as the fallback, with storage disabled, so content is not retained to train models. Bid evaluation asks the buyer to confirm before anything is sent. The website assistant has no access to any account or workspace at all, it can read published product information and nothing else.
Data returned by in-app tools is treated as untrusted input to the model, so text written by a third party (a supplier’s own profile notes, for instance) cannot be used to redirect the assistant. Full detail on AI disclosure.
Our own access
A small number of platform operators can assist with account problems. Their access is role-limited, every privileged action requires a stated reason and writes an audit record, and some capabilities are deliberately absent: there is no impersonation feature and no permanent delete in the operator console.
Secrets and API keys are server-side only and never reach the browser.
Reporting a vulnerability
If you find a security issue, please tell us before telling anyone else. Write to our security contact or use the contact form with the security reason selected.
Include what you found, how to reproduce it, and what you think the impact is. We will acknowledge within three business days and keep you updated. We will not pursue legal action against anyone who reports in good faith, avoids privacy violations and service disruption, and gives us reasonable time to fix it before publishing. We do not currently run a paid bounty programme, and we would rather say so than imply one.
Questions about this policy?
A person reads every message. Get in touch and we’ll answer. Or ask Gero, our AI assistant, to walk you through what this page says - the answers explain, they don’t bind.