TradeLife legal
Security Overview
How TradeLife approaches account, organisation and financial-data security without publishing sensitive implementation detail.
Current high-level overview
01
Access control
- Organisation and role boundaries are enforced server-side and are designed to fail closed.
- Company financial areas are restricted to appropriate owner or admin users with the required active seat.
- Field users are not granted company-wide financial access merely because they are assigned to a job.
02
Data protection and releases
- Sensitive provider credentials are kept out of client-side code.
- Production database policies and application checks are used together for tenant isolation.
- Accepted proposal and financial evidence is preserved so later edits do not silently rewrite accepted commercial truth.
- TradeLife uses controlled releases, production deployment locking and audit evidence. Security reports can be sent to [email protected].