Security and responsibility

How ConsignEngine protects store data.

ConsignEngine handles operational, personal, and financial records for independent stores. Our security model begins with explicit store isolation, narrow access, and preserved business history.

Current controls, plainly stated.

This page does not imply a certification, audit, or compliance status that is not expressly named.

Security measures

How we protect store data.

01

Keep each organization’s data separate

Organizations and stores have explicit identities throughout the application. Customer-facing database tables use row-level security so a signed-in user’s access is constrained to authorized store membership.

02

Control what each staff role can do

Owners assign staff roles. Sensitive store operations check authorization at the application and database boundaries rather than relying on a hidden button alone.

03

Sign-in and account security

Supabase Auth provides account sessions and email confirmation. Public signup and account-recovery flows use server-enforced anti-automation checks and controlled error messages.

04

Keep completed financial records unchanged

Completed sales, tenders, payouts, and corrections are treated as business evidence. Sensitive financial changes use attributable records and audit history instead of silently rewriting the original transaction.

05

Separate card and subscription payments

Subscription payment details are entered through Stripe-hosted Checkout. Store card terminals remain separately operated; ConsignEngine records provider references and instructs staff never to enter a card number.

06

Production safety checks

Production configuration is bound to the approved ConsignEngine hosting and database projects. Release checks reject mismatched production identities instead of falling back to another store or environment.

What your store must manage

Your store also has security responsibilities.

Store owners remain responsible for who receives an account, which role they receive, the security of counter devices and inboxes, and promptly removing access that is no longer needed.

  • Use a unique account for each staff member
  • Choose strong, unique passwords
  • Review roles when responsibilities change
  • Lock counter devices when unattended
  • Never put card numbers in notes or references
  • Report unexpected access or activity promptly

Report a concern

Report a security or privacy concern safely.

Email security@consignengine.com with a concise description, the affected ConsignEngine page, and a safe way to reproduce the issue. Do not include passwords, private keys, card numbers, full database exports, or unrelated customer records.

If your procurement process requires a questionnaire, third-party report, data-processing detail, or named certification, ask before purchasing. We will describe the evidence that currently exists without representing an unearned assurance.

Evaluate the real boundary

Ask the security questions your store needs answered.

Start your 14-day trial

No card required · One core plan

Your privacy choice

Google Analytics and Meta Pixel are active by default. Choose Necessary only to opt out. Privacy Policy.