We handle B2B transaction data on behalf of our customers. This page tells you exactly what we have in place today, and what we are working toward.
CleanEDI is an early-stage product. We will not claim certifications we do not have or SLAs we cannot back up. This page tells you exactly what is in place today and what is on our roadmap.
CleanEDI runs entirely on Microsoft Azure. The security foundations, physical security, network controls, and compliance certifications of the underlying infrastructure come with that.
Your data is hosted in the Azure region that serves your market, and Enterprise customers can run in-country. We do not move your data across regions without your explicit agreement.
All data between your systems and CleanEDI is encrypted using TLS 1.2 or higher. No plaintext connections accepted.
All stored message data, partner configuration, and audit logs are encrypted at rest using AES-256 via Azure Storage Service Encryption.
Encryption keys are managed via Azure Key Vault. No encryption keys are stored alongside the data they protect.
All CleanEDI service-to-service communication uses Azure Managed Identity. No credentials are stored in configuration files or environment variables.
Every service and function runs with the minimum permissions required. No broad access roles are used.
All API calls, message processing events, and configuration changes are logged with timestamps, actor, and outcome. Log retention depends on your plan.
CleanEDI is built on the assumption that things will fail. Individual services restart, network calls time out, downstream systems go offline. The platform is designed to handle all of these without losing data or requiring manual intervention.
Formal DR documentation with defined RTO and RPO targets is in progress and will be available to Enterprise customers in Q3 2026. If you need this before then, get in touch and we will work through it with you directly.
Request security overviewMessages are persisted to durable storage before processing begins. A restart mid-processing does not lose the message.
Failed processing attempts are retried with exponential backoff before moving to the dead-letter store.
Failed messages are visible, inspectable, and replayable. Nothing is silently dropped.
All persistent data stores support point-in-time restore in the event of data corruption or accidental deletion.
Core services are deployed across Azure availability zones, providing resilience against single data centre failures.
We are an early-stage product. We do not have ISO 27001 or SOC 2 yet. Here is our honest roadmap.
If you discover a security vulnerability in CleanEDI, please report it directly at security@cleanedi.com. We will acknowledge your report within 24 hours and work to resolve confirmed issues promptly.
Enterprise customers can request a full security overview document before committing to a contract.