How we protect pilot data
Security
Last updated 2026-06-29
Security practices for the StationMind private pilot. This describes the current state, not a certification.
Access & isolation
- Tenant isolation: each store/organization only sees its own data.
- Role-based access: owners, managers, staff, wholesalers, and support each see only what their role allows.
- Suppliers never receive retailer sales velocity, inventory, or margin.
Data handling
- Secrets and tokens are never returned in API responses or notifications.
- Important actions are recorded as audit/business events.
- Public storefront pages expose only public catalog fields of active suppliers.
Pilot status & recommendations
- This is a private/staging pilot, not a public production deployment.
- Use strong, unique passwords and do not upload sensitive data you are not approved to share.
- Report any security concern to security@stationmindai.example (pilot placeholder).
This is a plain-language pilot policy, not formal legal advice. Legal review is recommended before any public launch.