Security

Tenant, payment, device, integration, and support boundaries are designed to fail closed.

OrderDock uses scoped identity, server authorization, compound tenant filters, row-level policy, encryption, idempotency, immutable ledgers, verified webhooks, rate limits, audit, and recovery controls.

Data access

Every staff, customer, device, service, sandbox, embed, support, and webhook identity has a distinct credential and scope. Front-end visibility never substitutes for server enforcement.

Payment scope

Provider-hosted web collection and certified reader flows keep raw card data out of OrderDock. Payment state follows verified provider events and reconciliation.

Responsible disclosure

Good-faith reports are acknowledged, triaged by severity, handled confidentially, and tracked through remediation and coordinated disclosure. Testing must avoid privacy impact, data destruction, denial of service, and social engineering.