CourierBD

Security and data handling

Learn what CourierBD stores, encrypts, and deliberately does not expose.

Security and data handling

CourierBD stores only the order fields needed for courier handoff and operational history. Courier credentials and optional Meta page tokens use the enc:v1: envelope.

The API is not a security boundary for private data by itself. Tenant scoping, workspace authorization, encrypted credentials, and nginx hostname isolation must all remain active.

See the public privacy policy and data handling policy for the legal contract.