Never Retype

Security

It can read what arrives. It cannot touch anything.

Order entry sits between your customers and your warehouse, which makes it exactly the wrong place for software that acts on its own. So this one does not.

Documents behind glass, lit but out of reach

The four constraints

The parts that are not
up for configuration.

Read-only on the mailbox

The connection can list and read messages in the folder you point it at. It cannot send, reply, forward, move or delete. If somebody ever asks whether it could email your customers by mistake, the answer is that it has no ability to email anyone.

Drafts, never posts

Orders arrive in your order system in an unreleased state and wait for a person. There is no setting that turns this off. It is the single constraint everything else is built on.

Unsure means ask

Low-confidence fields are flagged, not filled. The software would rather hand you four questions than one confident error, because the confident error is the one that ships.

Your documents stay yours

Your purchase orders and your catalogue are never used to train a model that touches another company. What it learns about your customers' formats is yours alone.

For whoever signs this off

The questions
procurement asks.

What exactly can it see?
One mailbox or folder that you nominate — normally the shared orders@ address. Not the rest of the tenant, not personal mail, not anything a person forwards from elsewhere unless it lands in that folder.
Where does the data sit?
In Canada or the United States, whichever you specify at setup, and it does not move between them afterwards.
How long are the source documents kept?
As long as you choose. Distributors usually keep them for the same period as the order record itself, so a disputed line can be traced back to the page it came from. It is a setting, not a policy we impose.
What happens if we leave?
You export the catalogue mappings and the order history, and the mailbox connection is revoked from your side, not ours. Revoking it is the off switch — there is no dependency on us doing anything.
Who at your end can see our orders?
Support access is off by default and time-boxed when you turn it on for a specific issue. Every access is logged and the log is visible to you.
Can we run a security review before we commit?
Yes, and on the Group tier it is expected rather than tolerated. Send whatever questionnaire your process uses to [email protected].
A single sealed document box on a shelf

Send us your questionnaire.

We would rather answer it before you are interested than after you have committed.