Postlytix← Back to site
Trust

Security at Postlytix

You're trusting Postlytix with data from across your business. Here's how we protect it.

Last updated: August 31, 2026

The short version: your data is encrypted, your workspace is isolated, we request the minimum access needed, and we never use your data to train AI models or share it with other customers. Nothing is ever written back to your systems without your approval, a dry run you can inspect, and a second sign-off on our side.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. Credentials and secrets are stored in a dedicated secrets manager, never in plain text.

Isolated workspaces

Each brand's data lives in a logically isolated workspace. One customer's data is never accessible to another.

Least-privilege access

We request the narrowest scopes needed for the work you ask for, and you can revoke any connected tool at any time.

No training on your data

Your data is used only to deliver the Service to you. We do not use it to train AI models, and we share with AI providers only the data needed to perform the analysis you request.

Human-in-the-loop by design

Postlytix never acts on its own. Approving a finding queues an action; it does not run one. Six checks stand between your approval and any write to your systems, all enforced on our servers rather than in the browser:

There is no customer-facing execute, approve or rollback route in the product at all. The permission check runs inside the execution engine itself, not only at the network route, so it holds even if a route is reached another way.

Every executed action is written to an audit log you can review, and most actions are reversible with rollback tested. Two are not, and we would rather name them than let you find them.

Internal helpdesk notes. Once an internal note or suggested reply is posted to a ticket, it cannot be un-posted through the helpdesk API. These are internal-only, are marked as not sent, and never reach a customer — but the write itself stands.

Carrier claims, depending on how you configure them. By default Postlytix does not touch your carrier portal at all. It assembles filing-ready claims — reconciled to the right shipments, with the order and tracking data already populated — and appends them to your team's existing claims tracker, or packages them for download. Your team files them. In that mode nothing is submitted to any carrier, and the rows we added can be cleared again. Direct submission to a carrier is a separate mode you have to enable deliberately, on your own carrier account; only in that mode is a claim irreversible, because a lodged claim cannot be withdrawn. The product tells you which mode an action will run in before you approve it, and refuses to execute if that configuration changed after your approval.

What Postlytix changes, and what it does not

This is the question most security reviews are really asking, so we answer it directly: Postlytix changes rules, not individual outcomes.

It does not decide a single transaction. It does not approve or deny a specific customer's return, price a specific order, or score a named person's profitability. What it does is find a pattern across many transactions, recommend a change to the rule that produced them, and — once you approve — update the artifacts that encode that rule: product content, ad set configuration, marketing flow definitions, customer segments. Individual outcomes then resolve correctly downstream because your own systems are applying the rule you chose.

Changes to policy itself — your return terms, your pricing — are surfaced and recommended only. A human decides those, always.

Data retention and deletion

What we hold. Read-only data pulled from the tools you connect (order, fulfillment, support, marketing and ad records) as an analysis snapshot; the findings computed from it; records of any action taken on your systems; and your account and connection details. Credentials are covered separately below.

Where it lives. In our Cloudflare database and object storage, logically separated per brand. Every query is filtered by brand, and that filter is enforced inside the engine as well as at the route.

How long we keep it. Analysis data is retained for the duration of your engagement so that findings remain reviewable and executed actions remain reversible. We do not sell it, and we do not use one customer's data to inform another customer's findings.

Deletion. You can ask us to delete your data at any time, in writing, and we will complete it within 30 days — analysis snapshots, findings, uploads and stored credentials included. We do the same on offboarding without you having to ask. We retain a minimal record of actions executed against your systems for the remainder of the term, because that record is what makes an action auditable and reversible; the specifics are committed in the DPA.

Revoking access. Deletion is separate from access. The credentials you give us are yours to withdraw: you can revoke or rotate them from inside the connected platform itself — Shopify, Meta, your helpdesk — at any time, with no request to us and no cooperation from us required. That cuts our access immediately, whatever else is in flight.

Credential handling

API keys and OAuth tokens you provide are encrypted and used only to perform the analyses and approved actions you request. You can rotate or revoke them at any time, and we recommend scoping credentials to the minimum permissions Postlytix needs.

Subprocessors

We rely on a small, deliberately short list of vetted providers to host and process data on our behalf. Each operates under contractual confidentiality and security obligations. Our current subprocessors are:

We will give customers advance notice before adding a subprocessor that processes brand data. If you need this list contractually committed, it is included in our DPA.

Data Processing Agreement

Where we process personal data on your behalf, Postlytix acts as the processor and you act as the controller. A Data Processing Agreement, including standard contractual clauses for international transfers where applicable, is available on request — email [email protected] and we'll send our current DPA for signature. We'd rather you ask for it before you connect anything than after.

Compliance

We build to recognized security practices and support customer rights under the GDPR and CCPA/CPRA. A SOC 2 audit is in progress. We do not yet hold the attestation and will not claim it before it is issued; we're happy to discuss where we are in the process. We independently commissioned two full security reviews of the platform in 2026, covering the execution layer that writes to customer systems, and remediated every finding. We're glad to walk prospective clients through our current posture, our architecture, and a completed security questionnaire under NDA.

Responsible disclosure

If you believe you've found a security vulnerability, please email [email protected] with the details. We'll acknowledge your report and work with you to resolve it. Please give us a reasonable window to fix the issue before any public disclosure.

Questions

Security or data-handling questions before connecting your stack? Email [email protected], we'll walk you through it.

This page describes Postlytix's security approach in good faith and will evolve as the product matures. It is informational and not a contractual commitment; specific obligations are governed by your agreement with Postlytix.