Honest security information

Security at CleanEDI.

We handle B2B transaction data on behalf of our customers. This page tells you exactly what we have in place today, and what we are working toward.

Honest about where we are

CleanEDI is an early-stage product. We will not claim certifications we do not have or SLAs we cannot back up. This page tells you exactly what is in place today and what is on our roadmap.

Built on infrastructure you already trust

CleanEDI runs entirely on Microsoft Azure. The security foundations, physical security, network controls, and compliance certifications of the underlying infrastructure come with that.

Your data stays in your region

Your data is hosted in the Azure region that serves your market, and Enterprise customers can run in-country. We do not move your data across regions without your explicit agreement.

Encryption

Encryption in transit

All data between your systems and CleanEDI is encrypted using TLS 1.2 or higher. No plaintext connections accepted.

Encryption at rest

All stored message data, partner configuration, and audit logs are encrypted at rest using AES-256 via Azure Storage Service Encryption.

Key management

Encryption keys are managed via Azure Key Vault. No encryption keys are stored alongside the data they protect.

Data residency

In-region hosting

Customer data is stored in the Azure region that serves your market. We do not replicate it to other regions without your explicit agreement.

In-country for Enterprise

Enterprise customers can have a dedicated deployment inside their own country, in the Azure region that meets their data residency obligations.

Access controls

Azure AD authentication

All CleanEDI service-to-service communication uses Azure Managed Identity. No credentials are stored in configuration files or environment variables.

Least privilege

Every service and function runs with the minimum permissions required. No broad access roles are used.

Audit logging

All API calls, message processing events, and configuration changes are logged with timestamps, actor, and outcome. Log retention depends on your plan.

Message handling

Messages persisted before processing

Every inbound message is written to durable storage before any processing begins. If a service restarts mid-processing, the message is not lost.

Idempotent processing

Duplicate messages are detected and discarded using message hash comparison. The same message will never be processed twice.

Message replay

All processed messages are retained and can be replayed. 30 days on Foundation, 90 days on Scale and Enterprise.

Dead-letter handling

Messages that fail processing after retries are moved to a dead-letter store. You are notified and can inspect and reprocess them.

Infrastructure

Azure-hosted

CleanEDI runs on Microsoft Azure, which holds ISO 27001, SOC 2 Type II, PCI DSS, and many other certifications at the infrastructure level.

No shared tenancy on Enterprise

Enterprise customers can opt for a dedicated deployment where their data and processing is completely isolated from other customers.

Automated backups

All persistent data stores are backed up automatically with point-in-time restore available.

Monitoring and alerting

All services are monitored via Azure Monitor and Application Insights. Anomalies and failures trigger alerts to the CleanEDI operations team immediately.

What happens when something goes wrong.

CleanEDI is built on the assumption that things will fail. Individual services restart, network calls time out, downstream systems go offline. The platform is designed to handle all of these without losing data or requiring manual intervention.

Formal DR documentation with defined RTO and RPO targets is in progress and will be available to Enterprise customers in Q3 2026. If you need this before then, get in touch and we will work through it with you directly.

Request security overview

No message loss on service restart

Messages are persisted to durable storage before processing begins. A restart mid-processing does not lose the message.

Automatic retry on failure

Failed processing attempts are retried with exponential backoff before moving to the dead-letter store.

Dead-letter visibility

Failed messages are visible, inspectable, and replayable. Nothing is silently dropped.

Point-in-time restore

All persistent data stores support point-in-time restore in the event of data corruption or accidental deletion.

Azure availability zones

Core services are deployed across Azure availability zones, providing resilience against single data centre failures.

What we are working toward.

We are an early-stage product. We do not have ISO 27001 or SOC 2 yet. Here is our honest roadmap.

ISO 27001 certificationPlanned2026
SOC 2 Type II reportPlanned2027
Formal DR and BCP documentationIn progressQ3 2026
Penetration testing (third party)In progressQ3 2026
Security overview document for enterprise buyersIn progressQ2 2026
Customer-facing audit log accessPlanned2026

Found a security issue?

If you discover a security vulnerability in CleanEDI, please report it directly at security@cleanedi.com. We will acknowledge your report within 24 hours and work to resolve confirmed issues promptly.

Report a vulnerabilityGeneral security questions

Need more detail?

Enterprise customers can request a full security overview document before committing to a contract.