Keep each organization’s data separate
Organizations and stores have explicit identities throughout the application. Customer-facing database tables use row-level security so a signed-in user’s access is constrained to authorized store membership.
Security and responsibility
ConsignEngine handles operational, personal, and financial records for independent stores. Our security model begins with explicit store isolation, narrow access, and preserved business history.
Current controls, plainly stated.
This page does not imply a certification, audit, or compliance status that is not expressly named.
Security measures
Organizations and stores have explicit identities throughout the application. Customer-facing database tables use row-level security so a signed-in user’s access is constrained to authorized store membership.
Owners assign staff roles. Sensitive store operations check authorization at the application and database boundaries rather than relying on a hidden button alone.
Supabase Auth provides account sessions and email confirmation. Public signup and account-recovery flows use server-enforced anti-automation checks and controlled error messages.
Completed sales, tenders, payouts, and corrections are treated as business evidence. Sensitive financial changes use attributable records and audit history instead of silently rewriting the original transaction.
Subscription payment details are entered through Stripe-hosted Checkout. Store card terminals remain separately operated; ConsignEngine records provider references and instructs staff never to enter a card number.
Production configuration is bound to the approved ConsignEngine hosting and database projects. Release checks reject mismatched production identities instead of falling back to another store or environment.
What your store must manage
Store owners remain responsible for who receives an account, which role they receive, the security of counter devices and inboxes, and promptly removing access that is no longer needed.
Report a concern
Email security@consignengine.com with a concise description, the affected ConsignEngine page, and a safe way to reproduce the issue. Do not include passwords, private keys, card numbers, full database exports, or unrelated customer records.
If your procurement process requires a questionnaire, third-party report, data-processing detail, or named certification, ask before purchasing. We will describe the evidence that currently exists without representing an unearned assurance.
Evaluate the real boundary
No card required · One core plan
Your privacy choice
Google Analytics and Meta Pixel are active by default. Choose Necessary only to opt out. Privacy Policy.