Least privilege
Access is limited to the data needed for the enabled workflow and assigned user role.
Security
NotERP Seller Profit & Ads Control uses least privilege, data minimization, access controls, encryption, audit logging, and incident response practices to protect seller data.
Access is limited to the data needed for the enabled workflow and assigned user role.
Seller data is encrypted in transit. Sensitive credentials are stored using protected secret-management practices.
Governed actions record evidence, requester, approver, execution status, and outcome review.
Security incidents are triaged, contained, investigated, and communicated according to documented response procedures.
The initial product scope avoids buyer PII and focuses on business operating evidence authorized by the seller.
The service does not sell seller data. Data sharing is limited to service providers needed to operate and secure the service.
Security contact
Email security reports to security@noterp.ai.
Please include the affected account, suspected impact, timestamps, and steps to reproduce when available.