Security controls that match the job the platform does.
RetailHawk handles operational, shopper and evidence data. The platform is therefore being built with identity, tenant isolation, evidence protection, recoverability and traceability as product requirements, not sales-page additions.
Implemented foundation
Strong identity
Laravel authentication with MFA/passkey support and secure recovery controls in the platform foundation.
Tenant isolation
Agency and client permissions are enforced server-side, with automated negative tests for cross-tenant access.
Private evidence storage
Evidence storage is isolated from the public application surface, with controlled retrieval and malware-scanning architecture.
Backup and restore
Database and object-store backup/restore checks are exercised as part of the operating environment.
Controlled promotion
Staging builds are verified before controlled production promotion; production does not build arbitrary branch code.
Independent security review
An independent application-security review remains a required release activity. No external certification is claimed here.
Data residency
The current RetailHawk 3 environment is hosted in the UK. We will only advertise additional residency options when they are formally available and contractually supported.
This page describes engineering controls in the current RHv3 programme. It is not a certification statement, penetration-test report or substitute for a customer-specific security review.
