Built for buyers whose legal team
has to say yes.
Retailopedia handles intelligence that would embarrass a CEO if leaked. That shapes every engineering choice. This page lists the controls we operate, the ones we’re building toward audit on, and the subprocessors your data touches. Nothing is hidden behind NDA.
Controls
We publish every control, whether shipping or roadmap. If something you need is marked Planned, tell us — it may be on the Flagship timeline already.
- Customer data stays in your VPC Flagship deployments run entirely in customer AWS/Azure account — inference, storage, audit log.
- Encryption at rest Managed relational DB + object storage · AES-256 (customer-managed KMS available on Flagship).
- Encryption in transit TLS 1.2+ everywhere · mTLS from edge to origin.
- Data residency (India) DPDP-aligned. Customer can pin primary region to ap-south-1 on Bespoke and above.
- SSO (SAML / OIDC) Microsoft Entra, Okta, Google Workspace supported on Scale and above.
- Role-based access Seat-level permissions scoped to briefs, brands, categories.
- Immutable audit log Every query, every citation, every seat action — retained 13 months.
- SOC 2 Type II Auditor selection in progress. Target window: Q3 2026 (3-month observation).
- DPDP self-assessment Published on request. Covers consent, purpose limitation, grievance officer.
- Penetration test (annual) First external pen test scheduled post-SOC 2. Full report shared under NDA.
- Vulnerability scanning Continuous scanning with a 4-hour patch cadence for OS-level findings.
- Signed container images Cryptographically signed (SHA384-ECDSA) on all shipping images.
- Software bill of materials (SBOM) Standards-compliant SBOM published per image. Available to Flagship customers on request.
- Incident response plan Named DRI · PagerDuty · Slack war-room · customer notification within 4 h.
- Post-mortems (public) Post-SOC 2 we publish a rolling 90-day incident log on /status.
Subprocessors
Every vendor that touches customer data. Updated whenever we add or retire one. Customers are notified in advance of any new material subprocessor.
Methodology summary
Every signal on Retailopedia is produced by a multi-agent editorial council that crawls public sources, deduplicates, scores for novelty, and writes a headline / deck / forecast / counter-view under editorial constraints. The full pipeline — crawl cadence, scoring rubric, counter-view requirement, supersede policy — is documented at /methodology.
Sources we read
Every publisher we currently track, with the number of signals Retailopedia has filed from that source. Each source name links to the source hub so a reviewer can audit what we've published from it.
Correction policy
If a signal is wrong, email [email protected] — we’ll investigate within 48 hours and, if confirmed, publish a correction with the updated date visible above the fold. Superseded signals stay in the archive with a visible superseded marker so citations can be audited.
Security contact
Responsible disclosure, audit questionnaires, DPA requests, and any procurement-gated security question — email [email protected]. Response within one business day.