Security

Security practices for operational data, integrations, and warehouse workflows.

ORCA is built for businesses that depend on accurate inventory, fulfillment, financial, and customer data. Security, access control, retention, and responsible integration handling are part of the operating model.

Encryption

Traffic uses TLS in transit. Sensitive stored data and backups are protected with strong encryption controls.

Access control

Role-based permissions, least-privilege production access, administrative controls, and periodic access reviews.

Monitoring

Security and access logs, anomaly monitoring, and operational visibility for sensitive workflows.

Secure development

Code review, dependency awareness, patching, and implementation practices that protect operational systems.

Data minimization

Integration scopes and stored data are limited to what is needed to provide the authorized workflow.

Incident response

Documented procedures for detecting, investigating, remediating, and notifying when required.

Amazon SP-API handling

Amazon customer PII is used only for authorized operational workflows such as order fulfillment, shipment confirmation, and customer-required delivery activity.

  • Seller authorization required
  • Operational use only
  • Customer PII retained only as needed and deleted no later than 30 days after delivery unless a longer period is legally required

Integration data handling

Accounting, ERP, carrier, and marketplace integrations are handled with least-privilege access and used to support the workflows customers enable.

  • No sale of customer data
  • No advertising or cross-site tracking cookies
  • Revocation and deletion requests handled through support