Security
Security, answered like an evaluator's checklist.
When a distributor's IT or ownership asks "is this safe to run our business on?" — this is the honest answer.
Encryption everywhere
All traffic runs over TLS. Data at rest in Firestore and Cloud Storage is encrypted by default on Google Cloud. There is no 'encrypted tier' — it's the floor, not an upsell.
Tenant isolation
Every business operates in its own namespaced data environment. Your catalog, accounts, orders, and financials never mix with another tenant's, and no customer can query across boundaries — the data model enforces it, not just policy.
Real authentication & roles
Firebase Auth with email/password, role-based access control (admin, office, warehouse, driver, rep, retailer), and short-lived signed session cookies. Employees get individual accounts — no shared logins, so every action is attributable to a person.
Hardened API surface
Every write endpoint requires a valid session scoped to the right account — a store can only order and pay as itself; a driver can only post to their route. Edge middleware gates protected areas before any content renders, and security headers (frame, content-type, permissions policy) are set platform-wide.
Payments
Card and ACH payments run through hosted Stripe Checkout — card numbers never touch MohnMercantile servers. Webhooks are signature-verified; payments post to invoices automatically.
Your data is yours
Exportable anytime in standard formats — no hostage formats, no export fees. If you leave, you leave with everything. That's a policy, not a feature toggle.
Common questions
Where is the data hosted?+
Google Cloud — Firebase, Firestore, and Cloud Run in US regions. Enterprise deployments can run on dedicated infrastructure.
Who can see our data?+
Your employees, scoped by role. NeighborTechs engineers access it only for support and only with your awareness. Nobody else's customers can reach it.
What about uptime?+
Serverless infrastructure with no single point of failure. Operational surfaces (driver app, live boards) are designed to degrade gracefully — the driver app works fully offline and syncs when signal returns.
Compliance?+
SOC 2 / ISO certification is on the enterprise roadmap. Today the platform runs on Google Cloud's certified infrastructure with encryption, isolation, and audit-friendly scan/event logging built in.
Security questions we haven't answered here? Ask us directly — a human answers.