Tenant isolation
Business records are scoped to a workspace. Cross-workspace identifiers are treated as unavailable rather than trusted.
Security
Mercestack is designed around tenant boundaries, least-privilege access, encrypted credentials and traceable actions. This page describes the controls implemented in the product; it does not claim an external certification.
Business records are scoped to a workspace. Cross-workspace identifiers are treated as unavailable rather than trusted.
Workspace permissions guard API actions. Hiding a module in the browser is never treated as the security boundary.
Provider credentials are encrypted at rest and are not returned after connection setup.
Payment state changes follow server-side verification or a valid provider webhook signature.
Business, administrative, agent and automation actions create attributable audit and event records.
Tenant-scoped files support storage limits, checksums, malware scanning and time-limited signed access when object storage is configured.
Send a clear description and reproduction details. Do not include customer data unless requested through a secure channel.
Start with structure, connect the work, then automate with context.
Create your workspace