Crossflo policies
Security Policy
Last updated August 17, 2026
Crossflo stores marketplace credentials and catalog data, so we take a few clear measures to keep them separated and protected.
Account isolation
Every seller's listings, credentials, logs and billing records are scoped to their own account and enforced at the database layer, so one account cannot read another's data.
Access
Access to production systems is limited to the people who need it to operate the service.
Authentication is handled by our managed auth provider, including hashed credentials and optional Google sign-in.
Credentials you store
Marketplace API keys you save are used only for calls you initiate. You can replace or clear them at any time in Settings.
Reporting a vulnerability
If you believe you have found a security issue, please report it through the contact page with enough detail to reproduce it, and give us a reasonable window to fix it before disclosing publicly. We will not pursue action against good-faith research that avoids privacy violations and service disruption.
Questions about this policy? Reach us through the contact page or browse every policy on the policy index.