Price basis
Public price contextMTS-KE5 / E10 / diesel
Wholesale referenceICEBrent / gasoil / FX
Delivered offerSCFTax / freight / terms
Decisive: confirmed offer
Security / assurance standard

Security is a claim
that must be tested.

SCF protects identity, commercial terms and transaction evidence through separate trust boundaries. Access is denied by default, sensitive actions require stronger authority, and release depends on test and recovery evidence.

Defence in depth

Six boundaries an attacker must not cross.

A member marketplace handles identity evidence, commercial terms and delivery records. Each layer limits what a compromised user, service or administrator can reach.

01

Identity

Invitation-only named users; passkeys or hardware keys preferred; recovery and privileged actions require fresh, phishing-resistant verification.

02

Authorization

Every request is checked against organization, role, product, region and action. Database row policies provide a second tenant boundary.

03

Data

TLS protects transport. Sensitive fields use context-specific envelope encryption; documents use separate object keys and short-lived access.

04

Transactions

Supplier bank-detail changes, membership approval, limit changes and order release require separation of duties and a second approver.

05

Detection

Successful and failed sign-ins, permission denials, exports, changes and administrator actions enter a restricted, tamper-evident event stream.

06

Recovery

Immutable encrypted backups are useful only after timed restoration tests, key-recovery exercises and incident decisions have been rehearsed.

Precise language matters

Not every marketplace record can be end-to-end encrypted.

RECIPIENT-ONLY ENCRYPTION

Protected exchanges

A message or data-room package can be encrypted for named recipients when the platform does not need to search, match or calculate with its contents.

ENVELOPE ENCRYPTION

Operational records

RFQs, offers, approvals and orders must be processed by authorized services. Each sensitive context receives a data key protected by a separate key-management boundary.

TRANSPORT + STORAGE

Infrastructure baseline

TLS is required on every network path. Databases, queues, object storage and backups use separate identities, keys and access policies.

Assurance baseline

A control is complete only when its evidence exists.

SCF uses OWASP ASVS 5.0 Level 2 as the application baseline, with selected Level 3 requirements for administrative and high-value commercial actions, alongside applicable BSI guidance.

Identity service

A maintained OpenID Connect provider such as Keycloak; passkeys enabled; no local password table; tested invitation, recovery and revocation flows.

Session handling

Opaque random session tokens stored only as hashes; Secure, HttpOnly and SameSite cookies; rotation, idle and absolute expiry, and server-side revocation.

Tenant boundary

Deny-by-default application policy plus forced PostgreSQL row-level security under a runtime role that cannot bypass or own the policies.

Keys and secrets

OpenBao or an equivalent managed key service; distinct data, document, backup and audit keys; rotation and emergency access under dual control.

Uploads

Quarantine first; actual file type and malware checked; active content rejected or sanitized; encrypted storage and expiring, auditable download links.

Software supply chain

Pinned dependencies, reviewable infrastructure code, secret scanning, SBOM, signed build provenance and blocked release for exploitable findings.

Verification

Threat modelling, code review, SAST/DAST, independent penetration testing, tenant-escape testing, restore exercises and tracked remediation form the release gate.

Accountability

Named security owner, patch and incident SLAs, processor inventory, access reviews, breach assessment and an approved disclosure channel.

Login evidence

Record the event; minimize the personal data.

SCF records successful, failed, challenged, recovered and terminated sessions with time, outcome, account or identity hint, device signal and source IP evidence. Raw IP values are encrypted, excluded from normal administration, revealed only for an approved investigation and removed under the security retention schedule.

30 daysEncrypted raw-IP retention365 daysPseudonymous event retention2 peopleRaw-IP disclosure control
Responsible disclosure

Found a security issue?

Do not send credentials, personal data or exploit payloads through the ordinary form. Request the protected reporting channel and wait for written scope before testing.

COORDINATED DISCLOSUREA protected route from report to resolution

SCF validates the reporter, provisions an encrypted channel, agrees testing boundaries, preserves evidence and tracks remediation through closure.

Request protected channel
Membership assurance

Security continues after membership approval.

Organizations need named users, current roles, prompt leaver removal and a protected route for suspicious activity, lost authenticators and payment-detail changes.

Apply for membership