Organisation separation
Products, evidence and operational records are scoped to the active organisation. Authenticated API requests are checked against that workspace context.
ClearSKU is designed to keep each organisation’s records separate, make evidence changes traceable and preserve a human decision point.
ClearSKU supports evidence work; it does not replace your legal, technical or conformity-assessment responsibilities.
Products, evidence and operational records are scoped to the active organisation. Authenticated API requests are checked against that workspace context.
Owner, administrator, reviewer, contributor and viewer permissions restrict sensitive actions such as billing, membership and assessment sign-off.
Secure, HTTP-only session cookies, CSRF checks and restrictive browser security headers reduce common session and browser risks.
Time-based authenticator codes and single-use recovery codes are available for stronger account assurance.
ClearSKU separates presence, provenance, product matching and the configured rule outcome. That distinction stays visible in the interface and in stored records.
Only the information needed to explain the boundary is published here. Operational secrets and dependency details are not exposed through public health checks.
The production deployment uses PostgreSQL for application records and S3-compatible object storage for evidence files.
Subscription checkout and account billing management are handed off to Stripe; ClearSKU does not store full payment-card details.
Workspace owners have tools for organisation data export, closure requests and lifecycle handling.
Production checks cover the database, evidence storage, transactional mail, billing connection and persistent background worker.
Please send a concise description, affected URL and reproduction steps. Do not include customer evidence or exploit another organisation’s workspace.