Security
How we look after your product data.
What’s in place, stated plainly. For anything else, ask for a security review.
In place
How your data is protected.
Each company’s data kept apart
Your catalog data is kept separate from other companies’ data.
Encrypted in transit and at rest
Data is encrypted in transit, and at rest in our databases and file storage.
Role-based access
Build your own roles from individual permissions, and give integrations their own service accounts and API keys instead of sharing a person’s login.
Masked credentials
Secret fields such as marketplace passwords and tokens are masked in the app and API.
AI inside your permissions
Agent changes wait for your approval by default, and Zen AI and assistants connected through MCP can only do what the signed-in user is allowed to do.
Decisions and versions on record
Approvals and rejections of agent suggestions are recorded with who made them, and products keep a version history.
Good to know
Before your review.
Still curious? Email the founders
How is data encrypted in transit?
The app and API use HTTPS only, with TLS 1.2 or newer, and our database and cache accept only encrypted connections.
Are product image links public?
Yes, by design. Channel image versions and full-size image copies get permanent links that anyone with the link can open, so feeds and marketplaces can load them.
Is there an audit log we can review?
Not as a separate log. Agent suggestions show who approved or rejected them, and products keep a version history. Attribute edits from imports, the API and agents aren’t labeled separately from user edits.
Can we protect links we share with buyers?
Yes. A Brand Hub link can have a password or an expiration date, and you can turn a portal off or revoke a catalog link.
Questions from your security team?
We’ll take them through a security review.

