CURRENT CONTROLS
What we can stand behind today
Shop Rego uses HTTPS at the gateway with managed TLS certificates.
Authenticated requests are scoped to the active organization, with authorization checks at the application boundary.
Platform integration secrets are encrypted with AES-256-GCM under a server-held master key and are never returned to the browser.
Staff sessions are revalidated and can be invalidated when an account, role, location, or organization status changes.
Sensitive tenant and platform actions are recorded in immutable audit trails.
PostgreSQL backups run on a schedule and restoration is checked by an automated drill.
Supported provider callbacks use signatures or protected secrets and replay controls.
Shared customer documents use expiring, revocable links and record access events.