Security
Tenant isolation, encrypted OAuth tokens, audit logs, and sanitized sync operations.
QuickBooks and commerce credentials are stored on the backend only, and refresh tokens are encrypted before persistence.
Dashboard, mappings, sync jobs, audit logs, billing, and organization data are tenant-scoped and require authenticated access.
Webhook signatures are validated before asynchronous reconciliation work is queued.
Sensitive tenant pages and API responses should return no-store caching headers.
Raw OAuth tokens, QuickBooks secrets, and sensitive accounting payloads are not intended to appear in application logs.
Data retention and deletion behavior should be reviewed with legal and operations before production launch.
Security questions can be directed to security@commercebridge.app.