Trust and security

Product evidence deserves a clear security boundary.

ClearSKU is designed to keep each organisation’s records separate, make evidence changes traceable and preserve a human decision point.

OUR BOUNDARYSecure records. Visible reasoning. No automatic certification claims.

ClearSKU supports evidence work; it does not replace your legal, technical or conformity-assessment responsibilities.

Workspace protection

Controls built around real team use.

01

Organisation separation

Products, evidence and operational records are scoped to the active organisation. Authenticated API requests are checked against that workspace context.

02

Role-based access

Owner, administrator, reviewer, contributor and viewer permissions restrict sensitive actions such as billing, membership and assessment sign-off.

03

Session protection

Secure, HTTP-only session cookies, CSRF checks and restrictive browser security headers reduce common session and browser risks.

04

Multi-factor authentication

Time-based authenticator codes and single-use recovery codes are available for stronger account assurance.

Evidence integrity

A document is not treated as proof merely because it was uploaded.

ClearSKU separates presence, provenance, product matching and the configured rule outcome. That distinction stays visible in the interface and in stored records.

  • Source-aware recordsEvidence stays attached to its product, type and recorded source context.
  • Content fingerprintsCryptographic hashes support stored-file integrity checks and change detection.
  • Dated assessment revisionsSaving and locking creates a historical assessment record without describing it as approval for sale.
  • Human review remains explicitClearSKU can prioritise work, but qualified people remain responsible for the decision.
Production operations

A deliberately bounded service.

Only the information needed to explain the boundary is published here. Operational secrets and dependency details are not exposed through public health checks.

Shared production data

The production deployment uses PostgreSQL for application records and S3-compatible object storage for evidence files.

Provider-hosted billing

Subscription checkout and account billing management are handed off to Stripe; ClearSKU does not store full payment-card details.

Export and closure controls

Workspace owners have tools for organisation data export, closure requests and lifecycle handling.

Dependency readiness

Production checks cover the database, evidence storage, transactional mail, billing connection and persistent background worker.

Report a concern

Found a security issue?

Please send a concise description, affected URL and reproduction steps. Do not include customer evidence or exploit another organisation’s workspace.

Contact ClearSKU