We handle B2B transaction data on behalf of our customers. That means security is not optional. This page tells you exactly what we have in place today, and what we are working toward.
CleanEDI is built on the assumption that things will fail. Individual services restart, network calls time out, downstream systems go offline. The platform is designed to handle all of these without losing data or requiring manual intervention.
Formal DR documentation with defined RTO and RPO targets is in progress and will be available to Enterprise customers in Q3 2026. If you need this before then, get in touch and we will work through it with you directly.
Request security overviewMessages are persisted to durable storage before processing begins. A restart mid-processing does not lose the message.
Failed processing attempts are retried with exponential backoff before moving to the dead-letter store.
Failed messages are visible, inspectable, and replayable. Nothing is silently dropped.
All persistent data stores support point-in-time restore in the event of data corruption or accidental deletion.
Core services are deployed across Azure availability zones, providing resilience against single data centre failures.
We are an early-stage product. We do not have ISO 27001 or SOC 2 yet. Here is our honest roadmap for formal certifications and security milestones.
If you discover a security vulnerability in CleanEDI, please report it to us directly at security@cleanedi.com. We will acknowledge your report within 24 hours and work to resolve confirmed issues promptly. We ask that you give us reasonable time to address the issue before any public disclosure.
Enterprise customers can request a full security overview document before committing to a contract. Get in touch and we will send it within one business day.