TradePro HQ trust

Security

TradePro HQ is designed around business-scoped access, guarded customer output and cautious provider integrations.

Needs final legal review before public launch.

Business-scoped access

Roles and access are derived from trusted business membership. Browser metadata, local storage and account profile claims are not treated as app authorisation.

Customer portal safety

Customer portal views should remain token scoped, request limited and sanitized, and must not expose internal costs, margins, payroll, vehicle stock, audit logs, storage paths or full portal tokens.

Provider safety

Private Supabase, Stripe, email and SMS credentials stay server-side. Email, SMS and payment flows remain guarded and disabled unless explicitly configured.