Identity
Invitation-only named users; passkeys or hardware keys preferred; recovery and privileged actions require fresh, phishing-resistant verification.
SCF protects identity, commercial terms and transaction evidence through separate trust boundaries. Access is denied by default, sensitive actions require stronger authority, and release depends on test and recovery evidence.
A member marketplace handles identity evidence, commercial terms and delivery records. Each layer limits what a compromised user, service or administrator can reach.
Invitation-only named users; passkeys or hardware keys preferred; recovery and privileged actions require fresh, phishing-resistant verification.
Every request is checked against organization, role, product, region and action. Database row policies provide a second tenant boundary.
TLS protects transport. Sensitive fields use context-specific envelope encryption; documents use separate object keys and short-lived access.
Supplier bank-detail changes, membership approval, limit changes and order release require separation of duties and a second approver.
Successful and failed sign-ins, permission denials, exports, changes and administrator actions enter a restricted, tamper-evident event stream.
Immutable encrypted backups are useful only after timed restoration tests, key-recovery exercises and incident decisions have been rehearsed.
A message or data-room package can be encrypted for named recipients when the platform does not need to search, match or calculate with its contents.
RFQs, offers, approvals and orders must be processed by authorized services. Each sensitive context receives a data key protected by a separate key-management boundary.
TLS is required on every network path. Databases, queues, object storage and backups use separate identities, keys and access policies.
SCF uses OWASP ASVS 5.0 Level 2 as the application baseline, with selected Level 3 requirements for administrative and high-value commercial actions, alongside applicable BSI guidance.
A maintained OpenID Connect provider such as Keycloak; passkeys enabled; no local password table; tested invitation, recovery and revocation flows.
Opaque random session tokens stored only as hashes; Secure, HttpOnly and SameSite cookies; rotation, idle and absolute expiry, and server-side revocation.
Deny-by-default application policy plus forced PostgreSQL row-level security under a runtime role that cannot bypass or own the policies.
OpenBao or an equivalent managed key service; distinct data, document, backup and audit keys; rotation and emergency access under dual control.
Quarantine first; actual file type and malware checked; active content rejected or sanitized; encrypted storage and expiring, auditable download links.
Pinned dependencies, reviewable infrastructure code, secret scanning, SBOM, signed build provenance and blocked release for exploitable findings.
Threat modelling, code review, SAST/DAST, independent penetration testing, tenant-escape testing, restore exercises and tracked remediation form the release gate.
Named security owner, patch and incident SLAs, processor inventory, access reviews, breach assessment and an approved disclosure channel.
SCF records successful, failed, challenged, recovered and terminated sessions with time, outcome, account or identity hint, device signal and source IP evidence. Raw IP values are encrypted, excluded from normal administration, revealed only for an approved investigation and removed under the security retention schedule.
Do not send credentials, personal data or exploit payloads through the ordinary form. Request the protected reporting channel and wait for written scope before testing.
SCF validates the reporter, provisions an encrypted channel, agrees testing boundaries, preserves evidence and tracks remediation through closure.
Request protected channelOrganizations need named users, current roles, prompt leaver removal and a protected route for suspicious activity, lost authenticators and payment-detail changes.
Apply for membership