SECURITY & SERVICE SCOPE
Know what protects the process.
Countercheck v0.3 is an early-access supplier-change review application. This page describes implemented controls and current limitations; it is not a certification or guarantee.
Identity and organizations
Customer sign-in uses a verification code sent by the configured email identity provider. The browser receives a private session cookie; encrypted provider credentials stay on the server. Sessions expire after eight hours or one hour of inactivity. Customers can sign out other devices from their account page. Organization membership and roles are checked on the server. A request cannot select its own reviewer identity. Invitation tokens expire after seven days, are stored as hashes, and are bound to the invited email.
Independent review
The person establishing a supplier record cannot independently confirm it. The person completing a change review cannot have created that request or recorded evidence for the current revision. Revising requested bank details invalidates earlier approval and evidence checks.
Records and attachments
Organization records use Cloudflare D1 storage. Attachments use private R2 storage and authenticated downloads. PDF, PNG and JPEG files are limited to 5 MB and checked for matching file signatures. They are downloaded as attachments, rather than rendered as active page content.
File hashes record the bytes stored. They do not establish that a document is authentic. Automated malware scanning and independent bank-account verification are not connected.
History and exports
Review and organization events are preserved by the application. Customer-facing tools do not provide a history reset. Administrators can export case evidence, the request register, organization records and a full backup with attachment bytes and checksums. Backups exclude sign-in sessions, invitations and billing credentials. A local recovery check has been implemented; production recovery arrangements remain the operator’s responsibility. Exports are not independently signed or tamper-proof attestations.
Before live financial use
The operator must complete business and legal setup, confirm the retention and recovery process, validate billing, test with separate real team accounts, and obtain an independent security review. Until those launch checks are complete, evaluate with sample data.
No SOC 2, ISO 27001 or other compliance certification is claimed. Countercheck does not move money, issue payment authorization or guarantee that a bank account belongs to a supplier.