Data Security & Compliance Architecture
Last verified: 17 August 2026
1. Security Architecture Overview
At SP Commission Shop, safeguarding commercial trade inquiries, grower payment calculations, and price threshold subscriptions is built into every layer of our technical architecture. We implement defense-in-depth security across transit, application, and database tiers.
Encryption in Transit
All data transmitted between web visitors, mobile devices, and our server infrastructure is encrypted using mandatory TLS 1.3 / HTTPS with modern HSTS headers.
PostgreSQL Row Level Security
Database tables (RFQs, market alerts, subscriber emails, and customer enquiries) are strictly isolated with PostgreSQL RLS policies preventing unauthorized public reads.
Server Actions & Secret Isolation
Privileged master keys and database credentials reside exclusively in isolated Next.js Server Actions, ensuring zero secret leakage into client browser bundles.
Parameterized Query Protection
All form submissions and API handlers utilize parameterized PostgreSQL queries and schema validation to completely eliminate SQL injection and XSS vectors.
2. Sensitive Data Handling & Commercial Privacy
We treat grower and buyer trade information with strict commercial confidentiality:
- No Third-Party Tracking: We do not deploy intrusive third-party data tracking networks or sell buyer lists to marketing agencies.
- Sanitized Error Logging: Client-side runtime telemetry is stripped of personally identifiable information (PII) before storage.
- One-Click Unsubscribe Tokens: Every automated price alert includes a cryptographically secure UUID unsubscribe link for instant removal.
3. Responsible Vulnerability Disclosure
If you identify a security anomaly or potential vulnerability in our digital systems, we encourage responsible disclosure. Please notify our technical security team immediately at:
We review all technical vulnerability reports within 24 business hours and appreciate collaborative disclosures.