Security and data handling

Customer RFQ data requires explicit boundaries.

Industrial requests can contain proprietary specifications, pricing and supplier information. Sorsivo treats security as a deployment decision backed by evidence—not a generic badge on a marketing page.

What a qualified implementation must establish.

01

Public website boundary

The public marketing site does not accept RFQ uploads. A product evaluation begins through an agreed, private workflow rather than an anonymous file-upload form.

02

Tenant and identity boundary

The product architecture binds private records and operations to an authenticated organization. Customer-specific access and denial evidence are verified for the deployment being evaluated.

03

External-action boundary

Sorsivo prepares work for review. Supplier messages, customer communication, technical equivalence and customer-facing prices require accountable human approval.

04

Model and training boundary

Sorsivo does not assume permission to train on customer data. Model providers, processing regions, retention behavior and permitted uses are documented in the implementation scope.

05

Retention and deletion

Retention, export and deletion requirements are agreed before live customer data is introduced and then verified against the selected deployment environment.

06

Evidence, not certification theater

Sorsivo does not claim SOC 2, ISO 27001 or another certification it has not earned. Security evidence is supplied for the exact implementation and deployment boundary under review.

Current assurance boundary

No unsupported certification claims.

Sorsivo's repository contains security, tenant-isolation, approval and operations controls. Production assurance still requires evidence from the exact deployed release, providers and customer configuration. We distinguish implemented controls from live verification.

  • Ask for the customer security review worksheet.
  • Confirm provider, region and retention choices before connecting data.
  • Require cross-tenant denial and external-send approval evidence.
  • Request a security review

Before implementation

Review the data boundary with us.

We'll document data sources, access, providers, retention, approvals and evidence requirements before live customer data is connected.Request the security review pack