total.supply / Security

Your catalog, orders and buyers — protected.

Security and privacy aren't a tier — they're the baseline. Here's how we protect your business and your buyers' data.

How we protect you

Built for procurement's checklist.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest for your catalog, orders and customer data.

You own payments

Funds settle to your own gateway. We never hold your money and never touch raw card data — PCI-DSS SAQ-A scope.

Privacy by design

GDPR and CCPA aligned. Data-processing terms, export and deletion on request, and regional hosting options.

Access control

Role-based permissions, least-privilege staff access, SSO on higher tiers, and a full audit log of changes.

Reliability

Redundant infrastructure, automated backups and monitored uptime, with an SLA on the Infrastructure tier.

Responsible AI

The copilot proposes; you approve. No customer data is used to train external models, and actions are logged.

FAQ

Security, answered.

Is total.supply PCI compliant?

You connect your own payment gateway, so card data is handled by your PCI-certified processor — keeping your store in the lightest PCI-DSS SAQ-A scope. total.supply never stores raw card numbers.

Is my data GDPR compliant?

Yes — we align with GDPR and CCPA, offer a data-processing agreement, support data export and deletion, and provide regional hosting options on request.

Do you offer SSO and audit logs?

Single sign-on is available on higher tiers, and a full audit log of catalog, order and settings changes is built in.

Does the AI use my data to train models?

No. Your customer and catalog data is not used to train external AI models. The copilot proposes changes and logs every action you approve.

B2B commerce depth

More context for teams evaluating total.supply.

total.supply is designed around a simple rollout: publish a buyer-ready catalog, capture demand, then add payments, marketplaces, integrations and controls as the business proves the need. That keeps launch lightweight without trapping the team in a shallow brochure site.

Catalog firstStart with the asset every B2B seller needs: searchable product pages buyers and reps can share.
Revenue controlUse your own payment providers and avoid platform revenue share as order volume grows.
Operational AIMove from content generation into approved operational tasks for quotes, products and orders.
Migration friendlyBring spreadsheets, PDFs and existing product pages instead of rebuilding from nothing.

Questions for your security team?

Send them our way — we'll get your procurement checklist signed off.