Understand the controls around your order data.
Poppelo implements tenant isolation, review gates, audit controls, retention, and tenant export. These controls operate on shared processing infrastructure; deployment verification matters alongside the implementation.
Tenant boundaries on shared infrastructure
Postgres row-level security (RLS) and request binding enforce tenant scope in the application data model. Workspace filesystem paths and LLM context are tenant-scoped. Processing infrastructure is shared: this is not a container-per-tenant service. Production roles, grants, pooler mode, and concurrency behavior remain deployment verification items in the capability ledger.
Review gates control consequential writes
Role checks, atomic review mutations, state guards, and durable dispatch support the review-to-delivery boundary. Confidence does not override validation or policy, and auto-approval is off by default. Uncertain destination writes require reconciliation evidence; an operator approval and a confirmed provider write are separate events.
Audit history and export controls
The implementation includes an append-only audit log and nightly WORM export code. These controls support investigation of changes and operational decisions. Production bucket Object Lock and retention settings, export operation, alert delivery, and incident drills remain unverified; code presence alone does not establish immutable production storage.
Retention and tenant lifecycle
Retention purging, tenant export, and offboarding capabilities are implemented. Plan suspension does not hard-delete the account. Discuss the retention policy, requested export, and offboarding requirements for your deployment; production lifecycle and export behavior still require verification. No universal retention duration is promised by this page.
Processing providers and legal information
The Privacy Policy describes service-provider processing, including AI processing and hosting, and the Terms of Service explain the agreement for using Poppelo. The Cookie Policy describes browser storage and optional analytics or monitoring. Use the contact page for current subprocessor details or requirements that need deployment-specific review.
Current assurance limits
Poppelo does not claim security certifications or independent compliance attestations on this page. The capability ledger records implementation and test evidence separately from deployment acceptance. Confirm the controls and evidence needed for your organization before processing data under requirements that depend on certification or a particular deployment configuration.
Questions about this workflow
Does every tenant get a dedicated processing container?
No. Poppelo uses shared processing infrastructure with tenant-scoped data access, workspace paths, and context.
Does implemented audit export establish production immutability?
No. Production storage configuration, Object Lock, retention settings, and export operation must also be verified.