Food trade software

Security

Last updated 27 September 2026.

Software only. We do not buy, sell, ship or hold money.

What we do today

The public site is served over HTTPS. Sessions, when accounts exist, will use cookies marked HttpOnly, Secure and SameSite. Card numbers are entered only in Stripe Checkout, so they do not touch our servers.

Administrative access is limited to people who need it. We do not put the owner’s private mailbox on the public site. Security reports go to privacy@vertexexport.com.

Encryption and access

Traffic between the browser and the site is encrypted with TLS. Data stored by the host is encrypted at rest where the host provides that control. Access to production systems is individual, not shared, and is removed when a person no longer needs it.

A future account system will add passkeys or a magic link, plus an authenticator-app second factor. SMS-only sign-in will not be the method. The design is written in docs/SECURITY_AUTH.md for the founder. It is not a public promise that every control is switched on before accounts open.

Incidents

If we confirm a breach of personal data, we will investigate, contain it, and notify affected customers and authorities when the law requires it. The Privacy Policy and the DPA describe the customer notice.

A machine-readable contact file is at /.well-known/security.txt.

Reporting a vulnerability

Email privacy@vertexexport.com with the subject “Security”. Give us a reasonable time to fix the issue before you publish it. Do not access other customers’ data, do not run a denial-of-service test, and do not demand payment. We will not sue a researcher who follows these rules and acts in good faith. This is not a paid bug-bounty programme.

Share this page