Skip to content

Security

Practical controls for quotes, files and billing

Tradient protects business accounts and customer-facing quote links with authentication, private storage, scoped public actions and payment-provider separation. This page describes what is in place, not buzzwords.

Controls

What protects your quotes

Authentication and roles

Managed authentication with owner, manager, staff and viewer roles. Access is scoped to the business account so people only see what their role allows.

Business data separation

Application and database controls keep one trade business’s quotes, customers and files separate from another’s.

Private file storage

Customer files and generated documents sit in private storage. Access uses authorised requests or time-limited links where appropriate.

Signed quote links

Customer-facing quote actions use unguessable private links with scoped server operations, validation and abuse protection. Sent quote content is frozen so later edits cannot silently change what the customer accepted.

Encryption in transit

Traffic is protected in transit by the hosting providers used by Tradient. Sensitive operations are validated on the server.

Rate limiting and abuse controls

Public quote actions include rate limiting, idempotency controls and CAPTCHA-style abuse protection where required to reduce automated misuse.

Payment-provider separation

Stripe handles subscription checkout and the billing portal. Tradient verifies billing webhook events before updating plan access and does not store full card details in its application database.

Email delivery controls

Transactional email is sent through a dedicated provider for quote notifications and account messages, separate from marketing spam practices.

Subprocessors

Specialist providers we use

Information may be processed outside New Zealand where these services operate, under their terms and safeguards. See also the privacy policy.

  • VercelHosting and edge delivery
  • SupabaseDatabase, auth and private file storage
  • StripeSubscription billing
  • ResendTransactional email
  • CloudflareSecurity and network controls
Reporting

Responsible vulnerability reporting

If you believe you have found a security or privacy issue, email info@tradient.co.nz with enough detail for us to investigate. We assess credible reports promptly and follow applicable New Zealand privacy-breach notification requirements.

We do not claim SOC certifications, penetration-test badges or uptime guarantees on this page. When those exist and can be verified, they will be listed here.

Security questions in the FAQ

Ready to quote with a private customer link?

Start a 14-day trial, no card required. Your quotes stay behind your business account until you send a private link.