ReconzoReconzo

Security

Read access. Nothing else.

We connect to your marketplaces, gateways, couriers and banks with read-only access. We cannot move money, change an order, issue a refund, or write to your systems. That is how it is built, not a setting.

Certifications

We publish status and dates, not badges. Nothing appears here before it is issued.

In final stage

SOC 2 Type II

Available under NDA on issuance.

In final stage

ISO 27001

Available under NDA on issuance.

Complete

Penetration test

Third-party test complete with no vulnerabilities found. Summary available under NDA.

How we handle your data

Encryption

TLS 1.3 in transit, AES-256 at rest. Credentials held in a managed vault.

Access control

Permissions by entity, channel and function, with approvals on anything privileged.

Audit log

Every read, export, rule change and claim action logged with who, when and what changed. Exportable.

Residency

Storage and processing set to your policy and the law that applies to you, written into your agreement.

Retention and deletion

Retention set by contract. Export and deletion on request, with a certificate of deletion.

Sub-processors

Published list with purpose and region. You are notified before anything is added.

Model training

Not by default, and never across customers without your written consent. We do not send your data to third-party model providers for training.

Portals without an API

Accessed with credentials you provide, limited to reporting and billing screens, every session logged.

Security questions

Can Reconzo move money or issue refunds?

No. Every connection is read-only. There is no payment initiation, no refund permission, and no write access to orders on any channel.

What do you use our data for?

Only to provide the services you sign up for. We may use it internally to improve our products, but we never sell it, and never share or use it for any other purpose without your explicit consent. Matching improves inside your own account and that learning never leaves it. We do not send your data to third-party model providers for training.

What happens to our data if we leave?

Full export in a machine-readable format on request, deletion within the SLA in your contract, and a certificate of deletion.

Can you complete our vendor security questionnaire?

Yes. We return completed assessments within two business days.