Trust
Security at ModernEDI
ModernEDI is built for business EDI workflows where access control, certificate handling, operational visibility, and reliable processing matter.
Account Security
ModernEDI uses managed authentication for user sign-in, password reset, account recovery, and related login security controls. Workspace users should use unique passwords, protect their email accounts, and keep integration credentials private.
Workspace Access Controls
Each workspace is isolated from other customer workspaces. Customer administrators control who is invited into a workspace and are responsible for assigning access only to users who need to participate in EDI, AS2, mapping, operational, support, or billing workflows.
Data Handling
ModernEDI stores account, partner, mapping, AS2, certificate metadata, transaction metadata, acknowledgements, MDNs, map results, and related operational records needed to provide the service. Customer content is handled to operate, secure, troubleshoot, and support the platform.
AS2 Certificates and Private Keys
ModernEDI helps customers generate and manage AS2 identity details used for partner onboarding. Certificate packages expose the public certificate and partner-facing details. Private keys are handled by ModernEDI and should not be shared outside the systems that require them for AS2 operation.
Integration API Keys
Integration API keys are intended for server-side use by customer systems. Customers should rotate keys when needed, avoid embedding them in public clients, and remove access for users or systems that no longer require it.
Logging and Monitoring
We use operational logging, monitoring, and alerting to diagnose platform issues, support onboarding, investigate security concerns, and maintain service reliability. Logs may include request metadata, service events, error details, and transaction-processing signals.
Responsible Disclosure
If you believe you have found a security issue, please contact us before disclosing it publicly. Include enough detail for us to understand and reproduce the issue. Do not access, modify, destroy, or exfiltrate data that does not belong to you, and do not disrupt service availability.
Security Contact
Security-related concerns can be sent to security@modernedi.com.