How it worksPricingDocsTry the decoder
Honest security information

Security at CleanEDI.

We handle B2B transaction data on behalf of our customers. That means security is not optional. This page tells you exactly what we have in place today, and what we are working toward.

Honest about where we are

CleanEDI is an early-stage product. We will not claim certifications we do not have or SLAs we cannot back up. This page tells you exactly what is in place today and what is on our roadmap.

Built on infrastructure you already trust

CleanEDI runs entirely on Microsoft Azure. The security foundations, physical security, network controls, and compliance certifications of the underlying infrastructure come with that.

Your data stays in your region

APAC customers have their data stored in Australian Azure data centres by default. We do not move your data across regions without your explicit agreement.

Encryption

Encryption in transit

All data between your systems and CleanEDI is encrypted using TLS 1.2 or higher. No plaintext connections accepted.

Encryption at rest

All stored message data, partner configuration, and audit logs are encrypted at rest using AES-256 via Azure Storage Service Encryption.

Key management

Encryption keys are managed via Azure Key Vault. No encryption keys are stored alongside the data they protect.

Data residency

APAC data in Australia

By default, all customer data for APAC customers is stored in Azure Australia East (Sydney). We do not replicate to overseas regions without explicit agreement.

Enterprise custom residency

Enterprise customers can request dedicated deployments in specific Azure regions to meet their own data residency obligations.

Access controls

Azure AD authentication

All CleanEDI service-to-service communication uses Azure Managed Identity. No credentials are stored in configuration files or environment variables.

Least privilege

Every service and function runs with the minimum permissions required. No broad access roles are used.

Audit logging

All API calls, message processing events, and configuration changes are logged with timestamps, actor, and outcome. Logs are retained for 90 days as standard.

Message handling

Messages persisted before processing

Every inbound message is written to durable storage before any processing begins. If a service restarts mid-processing, the message is not lost and will be reprocessed.

Idempotent processing

Duplicate messages are detected and discarded using message hash comparison. The same message will never be processed twice even if delivered more than once.

Message replay

All processed messages are retained and can be replayed. 30 days on Foundation, 90 days on Scale and Enterprise.

Dead-letter handling

Messages that fail processing after retries are moved to a dead-letter store, not silently dropped. You are notified and can inspect and reprocess them.

Infrastructure

Azure-hosted

CleanEDI runs on Microsoft Azure, which holds ISO 27001, SOC 2 Type II, PCI DSS, and many other certifications at the infrastructure level.

No shared tenancy on Enterprise

Enterprise customers can opt for a dedicated deployment where their data and processing is completely isolated from other customers.

Automated backups

All persistent data stores are backed up automatically with point-in-time restore available.

Monitoring and alerting

All services are monitored via Azure Monitor and Application Insights. Anomalies and failures trigger alerts to the CleanEDI operations team immediately.

What happens when something goes wrong.

CleanEDI is built on the assumption that things will fail. Individual services restart, network calls time out, downstream systems go offline. The platform is designed to handle all of these without losing data or requiring manual intervention.

Formal DR documentation with defined RTO and RPO targets is in progress and will be available to Enterprise customers in Q3 2026. If you need this before then, get in touch and we will work through it with you directly.

Request security overview

No message loss on service restart

Messages are persisted to durable storage before processing begins. A restart mid-processing does not lose the message.

Automatic retry on failure

Failed processing attempts are retried with exponential backoff before moving to the dead-letter store.

Dead-letter visibility

Failed messages are visible, inspectable, and replayable. Nothing is silently dropped.

Point-in-time restore

All persistent data stores support point-in-time restore in the event of data corruption or accidental deletion.

Azure availability zones

Core services are deployed across Azure availability zones, providing resilience against single data centre failures.

What we are working toward.

We are an early-stage product. We do not have ISO 27001 or SOC 2 yet. Here is our honest roadmap for formal certifications and security milestones.

ISO 27001 certificationPlanned2026
SOC 2 Type II reportPlanned2027
Formal DR and BCP documentationIn progressQ3 2026
Penetration testing (third party)In progressQ3 2026
Security overview document for enterprise buyersIn progressQ2 2026
Customer-facing audit log accessPlanned2026

Found a security issue?

If you discover a security vulnerability in CleanEDI, please report it to us directly at security@cleanedi.com. We will acknowledge your report within 24 hours and work to resolve confirmed issues promptly. We ask that you give us reasonable time to address the issue before any public disclosure.

Report a vulnerabilityGeneral security questions

Need more detail?

Enterprise customers can request a full security overview document before committing to a contract. Get in touch and we will send it within one business day.