Security & Trust

Built to protect sensitive merchant data.

Boarding a merchant means handling some of their most sensitive information. Adelite is built to encrypt it, restrict who can touch it, and keep a record of what happens.

Sensitive data is encrypted at rest and in transit.

The fields that matter most on a merchant application — Social Security numbers, dates of birth, bank routing and account numbers, and ID documents — are encrypted at rest and protected in transit. Where a field can be tokenized instead of stored in the clear, it is.

Access to that data is gated by role, and sensitive actions are logged.

Protected Fields
Social Security Number
Encrypted
Date of Birth
Encrypted
Bank Routing & Account
Encrypted
ID Documents
Encrypted

How access is controlled

Encryption protects the data. These controls govern who can reach it and what they can do.

Role‑based access control

Owner, Manager, Agent/Sub‑agent, Finance, and Read‑only roles — each sees only what their role allows.

Granular permissions

Control which tabs, functions, and buttons each role can view, click, and modify — at both the admin and ISO levels.

Audit logging

Sensitive actions are recorded, so there's a trail of who did what and when across the platform.

Least‑privilege by default

Roles are scoped to the minimum a person needs — sensitive data isn't exposed to people who don't require it.

Where we are, honestly

Roadmap

SOC 2 is a commitment, not a claim.

Adelite is not SOC 2 certified today. It's a deliberate roadmap commitment, and we'd rather say that plainly than imply a certification we don't yet hold. Our approach in the meantime is the same one a SOC 2 program is built on: encrypt sensitive data, enforce least‑privilege access, log what matters, and minimize what we store. If you have specific security or diligence requirements, raise them with us directly.

Have a security or diligence question?

We're happy to walk through how Adelite handles sensitive data, access, and logging for your situation.

Book a Demo