Skip to content
All posts
May 26, 2026·2 min read

Is our channel data safe with you? The security questions, answered

Before you upload a single VAR org tree, your security team will ask where the data lives, who can see it, and what gets logged. Here are the diligence questions worth putting to any channel tool — and our answers.

By The VAR Conduit team

Sooner or later a security team — yours, or your customer's — asks the uncomfortable question: where do the reseller org charts, rep contact details, and account-ownership records actually live, and who can see them? That data is some of the most sensitive in your business, and any tool asking to hold it — including ours — owes you a straight answer before you upload it. Here is the short version of ours; the full detail lives on our trust center.

Your data stays yours: tenant isolation

Tenant-owned business records carry the organization they belong to. Interactive application requests resolve the active organization before reading or changing tenant data, tenant cache keys include that organization, and database constraints protect key cross-workspace relationships. Global identity and control-plane records are kept separate from tenant business data.

Encryption controls

Browser and API traffic uses HTTPS. Hosted Postgres uses Supabase's managed at-rest storage controls, and CRM OAuth credentials receive a separate application-level AES-256-GCM envelope. Production secrets are supplied through server-side environment variables rather than application source.

Identity and access

Authentication and password verification are handled by Clerk. VAR Conduit supports an MFA gate that verifies both account enrollment and second-factor evidence for the current session when deployment configuration enables it; TOTP and passkey options depend on the Clerk project settings. Enterprise plans add SAML single sign-on and SCIM provisioning through a configured Clerk Enterprise Connection. Inside an organization, access follows the Admin, Member, and Viewer roles.

Audit logging, on by default

High-impact administrative operations such as imports, exports, role changes, credential changes, and erasure use mandatory audit writes; database mutations in that tier commit with their audit row or roll back. Session and denied-access markers are best-effort. Audit records carry structured actor/action context and minimized request metadata where available, and most rows remain subject to the workspace's configured retention policy. Eligible plans can export the filtered history to CSV for evidence collection.

Compliance posture

We publish whether product controls are available, a program is in progress, or an item remains on the roadmap on the security page. That page also states explicitly that VAR Conduit has not completed a SOC 2 audit and is not certified. If your procurement team has a questionnaire, that page is the place to start, and we are happy to fill in the rest.

Build the channel you wish you'd had.

See VAR Conduit on your real channel data — no sales pressure.