Security
Security is central to how LaventTech is built. This page describes our approach honestly — we do not claim certifications or audits we have not completed.
Tenant isolation
Each merchant's data is separated by architecture. Access is scoped so one merchant cannot reach another merchant's data.
Access control
Staff access is controlled per person and per role, including granular inbox and module permissions, so people only reach what they need.
Payment data
Integrated payments are planned. Where a payment provider is used, card data is handled by that provider using its secure components, so sensitive card details are not stored on LaventTech servers.
Merchant payment accounts and settlements remain separate to each merchant.
Secrets & data handling
Secrets and credentials are held server-side and not exposed to the browser. We apply reasonable technical and organisational measures to protect data.
Honest scope
We do not currently claim PCI certification, external security audits, or specific compliance certifications on this page. If and when we complete such steps, we will state them accurately.
This document is a pre-launch draft prepared for review. It will be dated and finalised before publication.
Singapore · info@laventtech.com
Questions about this policy? Email us and we'll help.
