Security at CONVSUPPLY

Protecting the supply chain data our network depends on.

Buyers and suppliers trust CONVSUPPLY with commercially sensitive demand, pricing and order information. This page sets out how we protect it today, and our roadmap toward ISO/IEC 27001 certification. It is published by the CONVSUPPLY team and reflects our current practices — we do not yet hold ISO 27001 certification.

How we protect your data

Security practices in operation

Encryption in transit

All traffic between your browser and CONVSUPPLY is served over HTTPS, protecting order, invoice and commercial data as it moves.

Row-level data isolation

Every table in our database enforces row-level security, so buyers, suppliers and administrators only ever see the records their role permits.

Authenticated access

Sign-in is required for all operational areas of the platform. Server-side checks re-verify identity on every protected action — never trust placed in the browser alone.

Role-based permissions

Buyer, supplier and admin roles are stored and validated separately, so no user can escalate their own privileges.

Full audit trail

Dispatch events, automation decisions and aggregation activity are recorded with timestamps and actors, giving a traceable history of every coordinated order.

Managed cloud infrastructure

CONVSUPPLY runs on managed cloud hosting with controlled releases, isolated environments and no user access to underlying systems.

Incident response

Security incidents are triaged, contained and communicated following a documented response process, with affected parties informed without undue delay.

ISO 27001 readiness

Our path to certification

ISO/IEC 27001 is the international standard for information security management. We are building our Information Security Management System (ISMS) around it and intend to pursue certification through an accredited body.

Step 1

Scope & risk assessment

Define the information assets CONVSUPPLY protects — buyer requirements, pooled demand data, supplier quotes, orders and invoices — and assess threats to their confidentiality, integrity and availability.

Step 2

Statement of Applicability

Select the Annex A controls that apply to our risks: access control, cryptography, supplier security, incident management, business continuity and staff awareness.

Step 3

Policies & training

Formalise the policies we already operate by — access reviews, secure development, data handling — and train everyone who touches the platform.

Step 4

Stage 1 audit

An accredited certification body reviews our documentation and confirms the ISMS is designed correctly.

Step 5

Stage 2 audit & certification

Auditors verify controls are operating in practice. Certification follows, with annual surveillance audits to maintain it.

Responsible disclosure

Found a security issue?

If you believe you have found a vulnerability in CONVSUPPLY, please report it to us privately before disclosing it publicly. Include a description of the issue, steps to reproduce it, and any supporting detail. We investigate every report and respond as quickly as we can.

Contact: security@convsupply.co