WAREHOUSEMARGIN

Trust & Security

Clear controls and clear limits. These statements describe the application implementation; they are not a security certification or a contractual SLA.

Identity, roles and tenant separation

ChatGPT Sites supplies sign-in identity. The application checks tenant membership, roles and plan access on the server. Current roles are administrator, operator, approver and read-only. Independent Entra/Google/SAML and configurable enterprise roles are not yet connected. Platform account MFA/session policy remains governed by the identity provider.

Approval security and audit

Customer links use random tokens stored as hashes, bounded expiry, revocation and source-version checks. New access requires an email code when delivery is configured. Responses retain the exact snapshot and a receipt digest. Email verification proves mailbox access, not legal signing authority. Audit events cannot be edited through normal application controls.

Evidence and encryption

The published site uses HTTPS. Evidence is stored in tenant-scoped object keys, checked for allowed file format and served as downloads. New uploads record a SHA-256 integrity digest. Provider-managed at-rest encryption, location and backup commitments require confirmation under the hosting agreement. No end-to-end encryption claim is made.

Malware scanning

File type/size checks and attachment downloads are implemented. Antivirus scanning and quarantine are not yet implemented; do not treat accepted files as certified safe. Agree a scanning service before a rollout that requires it.

AI data flow

Optional AI receives authorised tenant records through a server-side integration. Credentials are never sent to the browser. Recommendations must show reasons and evidence, and cannot approve charges, change rates or send communications.

Backups, recovery and availability

Backup/restore and incident runbooks exist for operator use. A production restore drill has not yet been verified. RPO, RTO, uptime and support response targets are not contracted here. Private readiness controls show configuration and recorded email failures; automated external alerting still requires setup.

Privacy, retention and reporting concerns

Review the Privacy Notice, DPA, Subprocessor List and Retention Policy drafts. Administrators can record data requests and export tenant records. Report suspected vulnerabilities or incidents through Contact without including credentials, approval tokens or sensitive evidence. A dedicated security mailbox must be established before production onboarding.