Security & Compliance
This page is maintained by Partner Bridge Commerce to answer common questions about how we handle your data. It describes practices we have in place today and certifications we are working toward — it is not an independent audit.
Controls in place today
- Encryption in transit and at rest
All connections to our app and database use TLS 1.2+. Uploaded merchant statements are stored in a private, encrypted-at-rest object store with server-side encryption.
- Least-privilege access
Customer data is protected by row-level security policies. Statement files live in a private bucket and are not publicly readable.
- Audit trails
Submission events, status changes, and views are recorded to an append-only audit log so we can investigate any unexpected activity.
- Input validation & file-type limits
Server-side schema validation, file-type allow-listing (PDF, PNG, JPG, WEBP), and per-file size caps (10 MB, up to 5 files) prevent malformed or oversized uploads.
- Tokenized payments — we never store card numbers
We don't handle raw cardholder data on our servers. Card capture happens through our PCI-aligned processing partners using tokenization.
Compliance roadmap
We're actively pursuing the following. Once an audit report or attestation is issued, we'll publish the report date and issuer here.
Privacy & cookies
We collect only what we need to respond to your inquiry: the contact information and merchant statements you choose to share. We do not sell your data. The site uses a small number of cookies to remember your preferences and to measure aggregate traffic.
To opt out of marketing or lead-related emails, visit our unsubscribe page. Transactional messages (like the status of a review you requested) will continue.
Reporting a security concern
If you think you've found a security issue, please email security@partnerbridge.com with details. We take all reports seriously and will respond promptly.