Security and data protection

Purchasing data names your suppliers, your prices and your people. Here is how it is held, in plain terms, and what we have not done yet.

Access

Authentication through Keycloak, with groups and permissions per role. Suppliers are restricted to their own records by row-level rules.

Audit trail

Every create, change and approval is recorded with its author and timestamp, and can be read back on the record itself.

Encryption

Encrypted in transit and at rest, with integration credentials held in a separate secret store.

Separation

Each customer's data is isolated, and no customer data is used to build features for anyone else.

Where the data sits

The platform runs on managed Kubernetes with a PostgreSQL database and object storage for documents. Transactional email is delivered by a provider operating from the United States, so those messages leave the EEA under the European Commission Standard Contractual Clauses.

Controller

SHARETEAL is the data controller. A data processing agreement is available on request.

Your rights

Access, correction, deletion, portability and objection, answered within one month. Write to contact@bluesourcing.io.

This website

Sets no cookies at all: no analytics, no advertising, no third-party script.