Trust

Security & data handling

RegMend handles sensitive supply-chain and compliance data on your behalf. Here is how we approach that responsibility in the current phase of the platform.

Controlled access

Every user is assigned a role — admin, operator, reviewer or client — and can only perform the actions that role allows. Client accounts are further scoped to their own organization.

Tenant isolation enforced at the database

Access control is not just a frontend check. Organization-level isolation is enforced by row-level security policies in the database itself, so a request cannot be crafted to reach another customer's data.

Immutable audit trail

Case creation, status changes, assignment, data corrections, document uploads, supplier requests, reviews and resolutions are all recorded as append-only events, tied to the acting user and a timestamp.

Original data is never overwritten

When RegMend corrects a value, the original is preserved as a separate, immutable snapshot alongside the correction. You can always see exactly what you sent us and exactly what changed.

Secure document handling

Uploaded evidence and source files are stored in private object storage with access limited to authorized users of the owning organization and RegMend staff. Files are never publicly accessible.

No unsupported invention

RegMend does not fabricate coordinates, boundaries, supplier or producer data, or evidence, and does not mark a case resolved just to improve statistics. When information is insufficient, the case is flagged, sent for review, or escalated.

RegMend is an early-stage operations platform. We do not currently hold formal certifications such as ISO 27001 or SOC 2, and we will not claim them until they have actually been obtained. If a specific security or compliance requirement is a condition of working together, tell us and we will address it directly.