Security · Data posture
Stated plainly, held to audit standards.
Procurement audit teams read pages like this one closely, so it says only what is true today - including what is still a target.
Data residency and encryption
Primary data stores are US-only, with no cross-border replication. Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256 through managed cloud services. SOC 2 Type I is on the roadmap, targeted for the second half of 2026 - we state that as a target, not a certification we hold today.
What we store
Form submissions (name, work email, company, topic, message), Tuesday Read subscriber emails and any regions they choose, vendor listing data (most of it from public business records, plus what a vendor adds when claiming), and first-party usage events that tell us which tools get used. We do not store payment card numbers - vendor membership billing runs through Stripe, and card data stays with Stripe.
Contact protection on the vendor network
Vendor contact details are never in the public page bundle and cannot be bulk-scraped or crawled. A buyer reveals contact info one vendor at a time, up to three per visit, only after submitting their own email. Removal is one email away: info@palletsolutionsusa.com, handled within one business day.
The wall
The published intelligence and the managed-program business are structurally separated. Market Pulse and PSCI cite federal sources - we translate the numbers, we do not author them. The vendor map ranks by distance only; paying never buys position. Buyer sourcing data is never shared with vendors, and vendor data is never shared with buyers. Managed programs are quoted separately, and using the free tools obligates no one to anything.
Wire and ACH fraud
Our office never makes changes to wire or ACH transactions via email. If you receive an email purporting to be from us with banking-change instructions, call 951-821-0364 to verify before acting.
Reporting an issue
If you find a vulnerability or believe data is exposed, email info@palletsolutionsusa.com with the details. A person reads every report and replies within 24 hours.
US-only primary data stores · TLS 1.2+in transit · AES-256at rest · SOC 2 Type I targeted H2 2026
