Accuracy matters: This overview describes our security approach without claiming certifications that are not expressly documented. Customers with specific security, regulatory, or procurement requirements should raise them during sales review.
1. Security approach
Summit One treats security as a shared, risk-based operating responsibility. Our program is intended to protect the confidentiality, integrity, and availability of the platform and customer information using administrative, technical, and organizational controls appropriate to a growing B2B cloud software provider.
We review controls in light of service changes, identified threats, customer commitments, business scale, and lessons from operational events. No security program can eliminate all risk, and this overview does not create a guarantee beyond an applicable written agreement.
2. Platform architecture and separation
The production service is designed around managed cloud infrastructure and segmented application responsibilities. Customer access is logically separated through application authorization and account membership. Production, development, and administrative activities are separated through configuration, credentials, and access practices appropriate to the environment.
We seek to minimize collection of sensitive information. Summit One does not intentionally store complete payment-card numbers and does not hold, pool, settle, or transmit customer funds. Payment providers and merchant accounts remain under the customer’s separate relationships.
3. Identity and access controls
- Access is based on job responsibility and legitimate operational need;
- Privileged access is restricted, reviewed, and removed when no longer required;
- Authentication safeguards are applied to administrative and production systems;
- Customer administrators control user invitations, roles, locations, and deactivation within available features;
- Access events and material administrative actions may be logged for security, support, and accountability; and
- Personnel and contractors with access to confidential information are subject to appropriate confidentiality obligations.
Customers should use unique credentials, appropriate role assignments, supported multi-factor authentication where available, timely offboarding, and secure endpoint practices.
4. Encryption and secrets
Connections to production web services are protected using modern TLS in supported configurations. Sensitive credentials and service secrets are managed separately from ordinary application content and are not intended to be embedded in public source code or customer-visible records.
Where supported by the underlying managed services and system design, production data is encrypted at rest. Encryption is one layer of security and does not replace access control, monitoring, retention, or secure customer behavior.
5. Secure development and operations
Our practices may include peer review for material changes, dependency and configuration management, controlled deployment processes, logging, monitoring, vulnerability remediation, and documented operational ownership. Changes are evaluated according to risk and tested before or during controlled release.
Security findings are prioritized based on potential impact, exploitability, exposure, and available mitigations. Timing may vary by severity and system complexity. Emergency changes may follow an expedited process with retrospective review.
6. Availability, backup, and recovery
Summit One uses monitoring and managed infrastructure capabilities to support availability. Backup and recovery practices are designed around the type and criticality of information. Recovery procedures may be tested periodically, and material issues are tracked for remediation.
Customers remain responsible for their own business-continuity procedures, local operating instructions, appropriate exports, and alternative order-handling processes during an outage. Unless expressly stated in a signed agreement, website descriptions are not a service-level agreement.
7. Incident response
We maintain procedures for receiving, triaging, investigating, containing, remediating, and documenting suspected security incidents. Responsibilities may include technical investigation, legal assessment, customer coordination, recovery, and post-incident improvement.
If we confirm a security incident affecting customer information, we will provide notice as required by applicable law and contract. Notices may describe known facts, likely impact, steps taken, and recommended customer actions. We may delay or limit details where required by law enforcement or necessary to avoid increasing risk.
8. Service providers and subprocessors
Summit One may use reputable service providers for cloud hosting, authentication, monitoring, communications, billing, analytics, and support. We evaluate providers based on the service, information involved, availability, security representations, contractual terms, and operational dependency.
Providers receive only the access reasonably necessary to perform their contracted function and remain subject to their own security and legal responsibilities. Customers may request available information about material subprocessors during procurement.
9. Customer security responsibilities
Security depends on appropriate customer configuration and behavior. Customers are responsible for:
- Keeping administrator and billing contacts current;
- Using unique credentials and protecting authentication devices;
- Granting the minimum permissions required and promptly removing former users;
- Verifying integrations, API credentials, imported files, and destination systems;
- Submitting only information necessary for legitimate order operations;
- Maintaining secure devices, networks, browsers, and local systems;
- Reviewing alerts, exports, audit information, and unusual activity; and
- Promptly reporting suspected compromise or misuse.
10. Security assurance and customer reviews
Summit One responds to reasonable customer security and vendor-review questions in proportion to the proposed relationship and information involved. Available materials may include this overview, contract terms, architecture descriptions at an appropriate level, and responses to targeted questionnaires.
We do not claim SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, or other certification or compliance status unless confirmed in a current written statement specifically issued by Summit One. Customers must not represent that Summit One holds a certification based solely on this overview.
11. Responsible vulnerability disclosure
We welcome good-faith reports that help protect customers and the platform. Email security@summitone.app with a clear description, affected URL or component, reproduction steps, potential impact, and a safe proof of concept where appropriate.
Researchers must:
- Avoid privacy violations, data destruction, service degradation, social engineering, physical testing, denial-of-service activity, and access to data beyond what is minimally necessary;
- Use only accounts and information they own or are expressly authorized to test;
- Stop testing and report promptly if they encounter customer information or obtain unauthorized access;
- Allow a reasonable remediation period before public disclosure; and
- Comply with law and not demand payment, threaten disclosure, or exploit a finding.
Summit One does not currently promise a bounty or payment. We will make reasonable efforts to acknowledge legitimate reports, investigate, communicate status when appropriate, and credit researchers who request recognition and follow these rules.
12. Security contact
Security reports: security@summitone.app
Customer support: support@summitone.app
Abuse reports: abuse@summitone.app
Do not send passwords, private keys, complete payment-card numbers, or customer data by ordinary email.