As your commerce operation grows across teams, systems, and regions, trust becomes your foundation. Tanqory Commerce Core gives you the controls, visibility, and safeguards that serious organizations require — built into every layer of the platform.
Available in all Commerce Core plans. Advanced controls included in Enterprise.
Define exactly who can do what, where, and when. Not broad buckets — precise, granular permissions that reflect how real organizations actually operate.
Control access at the resource level. View orders but not refund. Edit products but not publish. Permissions that map to real job functions and responsibilities.
Create custom roles for every function in your organization. From warehouse staff to finance teams to regional managers — each with exactly the access they need.
Split responsibilities across roles. Use role-based permissions to keep sensitive actions like refunds and discounts in the hands of the right people.
One system, many teams, many locations, many markets. Security isn't just about locking things down — it's about ensuring the right people have the right access at the right scope.
Team members see and manage only their locations. Warehouse staff in one region can't access another region's inventory. Regional managers see only their regions.
Operations in each market stay scoped to that market. Currency-specific transactions are managed by authorized users for that currency. Cross-market operations require explicit permissions.
Control who can manage each sales channel. Each channel can have its own access rules.
Invitation links expire automatically, so unused invites don't stay open. Add seasonal staff and contractors without leaving stale access behind.
Every action is logged. Every change is traceable. Every operation has a clear chain of custody. Essential for enterprise governance, compliance, and operational integrity.
Complete history of who did what, when, and why. Logs are append-only and retained per your plan, supporting compliance and incident review.
Track changes to orders, products, inventory, prices, customers, and configurations. See before/after states, timestamps, and the user who made each change.
Find specific actions instantly. Filter by user, date range, resource type, or action. Export audit logs for compliance reporting or investigation.
Track all API calls, webhook deliveries, and system integrations. Identify integration issues, monitor usage, and maintain security oversight.
Your integrations and custom applications need access too — but with the same rigor and control as human users. API security isn't optional.
Generate, rotate, and revoke API keys with confidence. Each key has clear ownership, purpose, and expiration. No orphaned keys or forgotten integrations.
Grant API access at the exact scope required. Read-only for analytics. Write access for order creation. Limited to specific channels or locations.
Protect your system from runaway scripts, integration errors, or malicious activity. Automatic throttling ensures system stability and fair resource allocation.
Security isn't just about protecting data at rest — it's about protecting operations, preventing mistakes, and ensuring business continuity.
Your data is yours alone. Logical isolation between tenants with controls to prevent cross-tenant access. No shared customer data between organizations.
Data is encrypted with TLS 1.2+ in transit and AES-256 at rest, with AES-256-GCM for application-layer secrets. Card details are tokenized by our payment provider and never stored by Tanqory.
Automated daily backups with 7-day retention. Your commerce data is protected against accidental deletion and corruption.
Prevent accidental bulk deletions. Require confirmation for destructive actions. Soft deletes with recovery periods. Protect your business from human error.
Some operations carry more risk than others. Financial actions, tax adjustments, bulk changes — these require additional controls and oversight.
Refunds are permission-gated by role, so only authorized team members can issue them. Limit refund access to reduce fraud exposure.
Control who can create and edit discounts by role. Keep pricing changes with the people responsible for them.
Tax changes are logged and restricted. Only authorized users can modify tax rates, exemptions, or configurations. Essential for compliance.
Bulk updates, imports, and deletions require confirmation. Preview changes before applying. Rollback capability for critical operations.
Security is proactive, not reactive. Detect unusual activity before it becomes a problem. Receive alerts when operational thresholds are exceeded.
Track failed login attempts and lock accounts automatically after repeated failures. Slow down brute-force attempts on your accounts.
Get notified when critical thresholds are crossed. High-value refunds, inventory adjustments, pricing changes — stay informed in real-time.
Monitor and log failed login attempts, permission denials, and unauthorized access requests. Identify potential security issues early.
Don't just document your policies — enforce them automatically at the system level. Reduce reliance on training, memory, and good intentions.
Add multi-factor authentication with TOTP, SMS, and backup codes. Passwords are stored using strong hashing.
Role-based access, audit logs, and data-deletion tools give your team the controls to support compliance programs and data-access requests.
Multiple departments, locations, and functions accessing the same system. You need granular control, audit trails, and operational boundaries that reflect your org chart.
Expanding into new markets, hiring remote teams, managing multi-currency operations. Security needs to scale with your growth — not slow it down.
You need audit-grade logs, separation of duties, and controls that satisfy regulators, auditors, and internal risk management.
High transaction volumes, customer PII, payment information, or regulated industries. Security isn't a feature — it's the foundation.