Encryption in transit
All traffic between your browser and CONVSUPPLY is served over HTTPS, protecting order, invoice and commercial data as it moves.
Buyers and suppliers trust CONVSUPPLY with commercially sensitive demand, pricing and order information. This page sets out how we protect it today, and our roadmap toward ISO/IEC 27001 certification. It is published by the CONVSUPPLY team and reflects our current practices — we do not yet hold ISO 27001 certification.
How we protect your data
All traffic between your browser and CONVSUPPLY is served over HTTPS, protecting order, invoice and commercial data as it moves.
Every table in our database enforces row-level security, so buyers, suppliers and administrators only ever see the records their role permits.
Sign-in is required for all operational areas of the platform. Server-side checks re-verify identity on every protected action — never trust placed in the browser alone.
Buyer, supplier and admin roles are stored and validated separately, so no user can escalate their own privileges.
Dispatch events, automation decisions and aggregation activity are recorded with timestamps and actors, giving a traceable history of every coordinated order.
CONVSUPPLY runs on managed cloud hosting with controlled releases, isolated environments and no user access to underlying systems.
Security incidents are triaged, contained and communicated following a documented response process, with affected parties informed without undue delay.
ISO 27001 readiness
ISO/IEC 27001 is the international standard for information security management. We are building our Information Security Management System (ISMS) around it and intend to pursue certification through an accredited body.
Scope & risk assessment
Define the information assets CONVSUPPLY protects — buyer requirements, pooled demand data, supplier quotes, orders and invoices — and assess threats to their confidentiality, integrity and availability.
Statement of Applicability
Select the Annex A controls that apply to our risks: access control, cryptography, supplier security, incident management, business continuity and staff awareness.
Policies & training
Formalise the policies we already operate by — access reviews, secure development, data handling — and train everyone who touches the platform.
Stage 1 audit
An accredited certification body reviews our documentation and confirms the ISMS is designed correctly.
Stage 2 audit & certification
Auditors verify controls are operating in practice. Certification follows, with annual surveillance audits to maintain it.
Responsible disclosure
If you believe you have found a vulnerability in CONVSUPPLY, please report it to us privately before disclosing it publicly. Include a description of the issue, steps to reproduce it, and any supporting detail. We investigate every report and respond as quickly as we can.
Contact: security@convsupply.co