Security
Your ERP data stays yours
Read-only access, encrypted at every layer, with RBAC and SSO support. We are honest about where we are and where we are going on compliance certifications.
Data security
Encryption in transit
All data in motion between your ERP connector and the Routeharvest platform uses TLS 1.2 or higher. API endpoints enforce HTTPS. No plaintext transport at any layer.
Encryption at rest
Your ERP transaction history is stored encrypted at rest (AES-256). Encryption keys are managed per-customer. Your data is never mixed with another customer's data at the storage layer.
SOC 2 control design
We design with SOC 2 Type II controls for security, availability, and confidentiality. Formal certification is in progress. We will publish a report when the audit is complete. We will not claim it before then.
Access Control
Role-based access and SSO
Routeharvest uses role-based access control (RBAC) to limit what each user can see and do. Planner roles can view forecasts and approve reorder recommendations. Admin roles manage integrations and user seats.
SSO support lets you enforce your existing identity provider policies across Routeharvest access. SAML 2.0 is supported on Growth and Scale plans.
| Feature | Starter | Growth | Scale |
|---|---|---|---|
| RBAC (Planner / Admin roles) | |||
| SSO (SAML 2.0) | |||
| Audit log (user actions) | 30 days | 90 days | |
| IP allowlist |
Compliance Posture
Where we are, honestly
We are a bootstrapped company founded in 2024. Our security posture is strong. Our formal certification roadmap is in progress and we will be direct about what we hold and what we are working toward.
Data minimization, purpose limitation, and customer data deletion are built into the platform architecture, not retrofitted. EU-based customer data stays within EU hosting zones.
The integration uses read-only credentials. Routeharvest never writes back to customer ERP or WMS systems. Credential scope is documented and auditable.
We are working toward formal SOC 2 Type II certification. We design with those controls in place. We will publish the report when the audit is complete, not before.
Need a security review before you connect?
We are happy to do a direct security review call. Send us your security questionnaire and we will fill it out honestly.
Request a security review