Trust Center

Security, privacy and data control

A factual view of PartnAir implementation and test status. These labels are not evidence of production operation, a penetration test or an independent certification.

Technical controls

Implemented and tested

Multi-tenant isolation

PostgreSQL RLS, garage/distributor scoping and automated pgTAP tests.

Implemented and tested

Access and secrets

Least privilege, hashed API keys and ERP secrets held in Vault without clear-text retrieval.

Implemented and tested

API and events

Scopes, rate limiting, idempotency, HMAC signatures, retries and dead-letter handling tested in code.

Implemented and tested

Traceability

Mutation audit, ERP correlation and logs designed to exclude credentials and sensitive payloads.

Implemented and tested

Resilience

Timeouts, bounded retries, circuit breaker, freshness-aware cache and manual fallback.

Prepared · validation required

Reversibility

Export, revocation and disconnection are implemented. The tenant-deletion procedure still requires environment acceptance testing before production use.

Assurance and compliance

DPA / GDPRPrepared · validation required
Processing registerPrepared · validation required
Automated RLS isolation testsImplemented and tested
Independent penetration testExternal validation required
ISO 27001 / SOC 2External validation required

Data lifecycle

  1. 1. Data minimisation. Data required for the service and the customer's instructions.
  2. 2. Isolated processing. Tenant isolation, governed suppliers and human approval for contractual actions.
  3. 3. Managed retention. Caches and technical logs have configured retention periods; execution must be monitored in production.
  4. 4. Return and deletion. The export path is implemented; tenant deletion remains subject to operational acceptance testing and legal obligations.

Sub-processors

The contractual list and transfer safeguards are set out in the DPA draft. This view reflects the current declared list.

ProviderPurposeLocationDeclared safeguard
Vercel Inc.Website and web application hostingUnited States / EU (edge)EU Standard Contractual Clauses
Supabase Inc.Database, authentication, file storageEuropean Union (Frankfurt)Hosted within the European Union
OpenRouter, Inc.Routing of requests to AI models (inference)United StatesEU Standard Contractual Clauses
Google (Gemini API)Generative and vision AI models (parts photo analysis)European Union / United StatesEU Standard Contractual Clauses
Resend, Inc.Transactional email deliveryUnited StatesEU Standard Contractual Clauses
Stripe Payments Europe, Ltd.Subscription payment processingEuropean Union (Ireland)Hosted within the European Union

Documentation last updated: 15 July 2026 · Contact: privacy@partn-air.com

Governed autonomy

The agent prepares. The responsible person decides.

Autonomy follows your rules, permissions and the risk of each action.

PartnAir can
Your team approves
01Structure a request and complete context
Ambiguous or missing information
02Search authorised sources
A sensitive or unproven substitution
03Prepare a quote or order
An out-of-policy price or commitment
04Detect a discrepancy and assemble evidence
The final resolution of a dispute