Security and data handling
A supplier's Scintilla data is competitively sensitive and contractually protected. Here is exactly how it is stored, who can see it, and what we will never do with it. Written plainly, so your buyer or your IT lead can read it in five minutes.
Where it lives
| Isolation | Each client is a separate tenant with its own warehouse and its own cockpit. Nothing is pooled or cross-tenant. There is no shared table anywhere that holds two clients' data. |
|---|---|
| Hosting | A managed cloud server we operate, reached only through Cloudflare's network. The application binds to localhost and is never exposed directly to the internet. |
| Sign-in | Cloudflare Access with a one-time code to an allow-listed email. No passwords to leak or reuse. Access is granted per person, per tenant, and removed the same way. |
| Who may change things | Signing in grants viewing. Write actions (refresh, ledger edits) are a separate allow-list, recorded in version control, so adding a viewer never grants change rights. |
| Encryption | In transit end to end through Cloudflare. At rest on encrypted volumes. |
| Releases | Every data publish is atomic: a new release is built and switched in one step, and the previous release is kept, so a bad load is rolled back with one command rather than repaired in place. |
| Secrets | Credentials live outside the codebase and are never committed. Per-tenant API keys are separate. |
What we will not do
No resale, no aggregation across clients, no benchmarking one supplier against another, no re-identification. Case-study figures are published only with the client's permission and with client and item identities withheld.
Your warehouse is yours. On termination it is returned and then destroyed, and we will put that in writing.
If something goes wrong with your data on our side, you hear it from us first, with what happened and what we did.
Walmart's program for third parties
Walmart Data Ventures runs a Verified Service Provider program for third parties that work with supplier Scintilla data, covering security, compliance and data-governance vetting, with an annual confirmation. We are pursuing verification and will list our status here when it is granted. Ask us where it stands.
This page describes our current practice in plain language. It is not a certification. If your vendor-risk process needs a questionnaire answered or a specific attestation, ask; we will tell you honestly what we have and what we do not.
Start here
Thirty minutes on a call, your data on the screen. If there is nothing there worth fixing, I will tell you that.
ericfritts@tenxanalytics.comEric Fritts · Founder · 479-713-0714 · Rogers, Arkansas