Trust center

Controls should be specific, testable, and honest.

Mainspring describes the controls in use today and clearly separates them from Enterprise capabilities that remain gated.

Control 01Available now

Data purpose

Collect only what the defined product or engagement requires.

Control 02Available now

Access

Name approved users, owners, and administrative responsibilities.

Control 03Available now

Retention and deletion

Document retention expectations and test deletion behavior where applicable.

Control 04Available now

Human review

Keep accountable review around uncertain or consequential outputs.

Control 05Available now

Evaluation

Use representative acceptance sets, failure cases, and release thresholds.

Control 06Founder-led

Monitoring and incidents

Define operating signals, escalation, recovery, and support boundaries.

Control 07Security-gated

Enterprise identity and isolation

SSO, roles, tenant isolation, and hardened audit controls follow paid proof.

Buyer commitments

Clear expectations before a proposal.

One-business-day response

Qualified corporate inquiries receive an initial human response within one business day. If Mainspring is not a fit, that is stated directly.

No silent scope expansion

Inputs, deliverables, exclusions, acceptance, and change control are written before paid work begins.

No invented proof

Representative scenarios and samples are labeled. Customer outcomes become case studies only after customer permission and evidence review.

Operational disclosures

Evaluation information in one place.

Subprocessors

Infrastructure and product vendors are disclosed in product-specific agreements before customer data is processed. No universal list is asserted where the service has not been selected.

Retention

Retention and deletion periods are defined by product or engagement. Corporate inquiries are used to respond and are not merchant application records.

Incident contact

Report a suspected security issue to hello@mainspringplatform.com with “Security” in the subject. Do not include secrets or sensitive records in the first message.

Infrastructure boundary

Product and service data remain separate.

The corporate site explains and qualifies work. Shopify installation, merchant access, product Billing, and storefront operation remain within the separate application.

01Shopify Billing stays with the app

02Service engagements use written scope and separate billing

03Enterprise controls graduate only after proof

Accessibility status

Designed for keyboard, readable contrast, responsive layouts, and reduced motion.

Accessibility is maintained as an operating practice, not claimed as a certification. Report accessibility issues to hello@mainspringplatform.com for investigation and correction.

Security questions

Discuss requirements before sensitive data is shared.

Start a security conversation