Transparent trust review
Security Controls
These controls describe the current Saleringo product architecture. Contractual commitments, audit reports, availability terms, and deployment-specific controls must be confirmed during procurement.
- Review owner
- Saleringo product security review
- Product baseline reviewed
- 18 August 2026
- Confirmed on this page
- Current product architecture and implementation controls
- Still requires approval
- Deployment controls, audit evidence, certifications, SLA, and contractual terms
Identity and least privilege
Protected operations resolve identity, active membership, workspace, tenant, region, and an exact permission rule before access.
- High-risk actions require step-up authentication and, where configured, human approval.
- Administrative support access is separately requested, approved, scoped, and audited.
- Secrets and payment credentials are not accepted through public forms or URLs.
Tenant and regional data boundaries
Control-plane records and regional tenant data use explicit boundaries with tenant-scoped access policies.
- Regional application tables enforce tenant-aware row-level security.
- Placement projections are versioned and reconciled rather than joined across databases.
- Data-region availability remains deployment-specific until approved for the customer.
Operational integrity
Commands are designed around atomic state changes, audit evidence, safe retries, and bounded provider calls.
- Idempotency records protect supported commands from duplicate effects.
- Transactional outbox and durable event handling separate state changes from delivery.
- Provider timeouts and late-result rejection are applied at sensitive boundaries.
Start a security or procurement review
Tell us the countries, channels, data categories, and deployment scope. You do not need to design the architecture before contacting us.