Security and data

The biggest fear in this niche is paying and not receiving the goods. Here is what you can verify: how refusals, refunds, code delivery and key-based access work — and where things stand with documents today.

Money

  • Refusal before charging

    If an item cannot be delivered — the price has changed, the supplier is unavailable, the item is closed for sale — the order is rejected BEFORE money leaves the balance. The checks come before the charge, not after.

  • Couldn't deliver — refunded

    If we charged but delivery failed, the order is closed with a refund and a separate line in the transaction log. A refund is an event in your log, not the outcome of a thread with support.

  • A retry does not cost twice

    A repeated request with the same idempotency key returns the response of the first order. A dropped connection, a retry from your queue or a button pressed twice do not lead to a second charge.

  • We do not trade at an unknown price

    If there is no way to verify the exchange rate, the catalogue responds with a refusal rather than serving an old price. Silence is more honest than a number whose age we do not know.

Codes

  • One code — one order

    Protection against repeat delivery is durable: it survives our restart and does not depend on what a process remembers. The same code cannot go into two orders.

  • Codes do not disappear

    Delivered codes stay with the order and can be re-read any number of times, including after our restart — the response is word for word the same. “Shown only once” does not happen here.

  • No third-party data in the response

    Only our envelope goes out: supplier names, responses and internal identifiers do not get into it. This is checked by a separate gate at every acceptance, not by trusting the code.

Access

  • Permissions belong to the key, not the person

    A key opens exactly the endpoints named in its permissions. A key for reading the catalogue will not place an order, even if asked to.

  • Address list

    If you have set a list of addresses your integration works from, the key is accepted only from them. A leaked key without your address is useless.

  • Revoke the key — and check subscriptions

    A revoked key stops opening endpoints immediately. But orders and event subscriptions belong to the COMPANY, not the key: a subscription set up by someone else survives the revocation and keeps sending your balance and orders to someone else's address. If you suspect a compromise, revoke the key AND open the subscription list, removing everything you did not set up.

Documents and personal data

At launch, settlements are made by crypto transfer. Invoiced work with a contract and accounting documents is a separate next step: a legal entity and accepting non-cash payments are in our plan but not yet open. We say this plainly because for a wholesaler the payment method is not a detail but a term of the deal.

The full text of the personal data processing policy is being prepared and will appear by launch. Until then we claim neither compliance nor certifications: a trust page that promises a document that does not exist devalues everything else on it. What exactly the site sets in the browser and when is already described on the cookies page — written from the code, not from memory.

Frequently asked

What happens to the money if an order is not delivered?

If delivery is impossible, the order is rejected before any charge. If the charge has already happened but delivery failed, the order is closed with a refund, and the refund appears as a separate line in the balance transaction log.

Can one code go to two buyers?

No. Protection against repeat delivery is durable and survives our restart, and a repeated request with the same idempotency key returns the response of the first order instead of creating a second one.

What should I do if an access key is compromised?

Revoke the key and IMMEDIATELY check the list of event subscriptions: subscriptions belong to the company, not the key, and survive its revocation — one set up by someone else will keep sending your balance and orders to someone else's address. Revoking alone is not enough. The list of addresses the key is accepted from and its permissions help limit the damage in advance: a read-only key will not place an order.

Do you work under a contract and provide accounting documents?

Not yet. At launch settlements are made by crypto transfer; a legal entity, invoices and accounting documents are the next step, and we will announce it separately. If you need accounting documents from the first shipment, tell us right away: it is better to agree on a timeline than to discover this after the deal.

Do you have a personal data processing policy?

The full text is being prepared and will appear on the site by launch. Until it is published, we do not claim compliance and do not publish company details — the list of what the site already sets in the browser and why is on the cookies page.

For suppliers

If you have volume in digital goods, we will tell you how we work and what is needed to get started.

For suppliers

Cookies — for the site to work and for analytics. Details

Security and data | Kodrio