认证状态
ShelfTap 已获得哪些认证——更重要的是,尚未获得哪些认证。
这些政策以英文发布。英文文本为准,译文仅供参考。
最后更新: 2026-08-01
本服务运营公司的注册信息尚未公布。信息确认后将显示在此处及页脚。
What we hold
Nothing. ShelfTap holds no information-security or privacy certification.
Stated plainly
- ISO/IEC 27001: not certified. No certification, no audit in progress, and none currently planned.
- SOC 2 (Type I or Type II): not attested. No report exists, no audit is under way, and none is currently planned.
- ISO/IEC 27701, PCI DSS, HIPAA, FedRAMP, Cyber Essentials: none of these apply to us and none are held.
- No independent penetration test has been commissioned or published.
If a procurement questionnaire asks for any of the above, the answer is no. We would rather lose the deal than imply a certification we do not have. If certification becomes a requirement for your organisation, tell us at support@shelftap.com — we will say honestly whether and when we could pursue it, and we will not put a date on this page until an auditor is engaged.
What we offer instead
In place of a certificate we publish the underlying detail, so it can be assessed directly:
- The 安全概览 page lists every control that is actually implemented — and a "what we do not claim" section listing the gaps.
- The 数据留存 page publishes the exact retention windows compiled into the service, plus the known limitation of the purge job.
- The 次级处理方 page names every third party and what each receives.
- The 事件响应 page states our breach-notification window.
- The 数据处理协议 is available for signature.
Ranking neutrality
A related commitment, since it is the other thing buyers ask us to certify: no payment of any kind affects the ranking of buyer search results. The result ordering is computed from an evidence-based ranking score and a contact-quality score only; no billing, verification or promotion field is read anywhere in that path. Paid verification and promotion apply solely to the separate supplier directory, where promoted entries are ordered above unverified ones. The two surfaces are kept apart deliberately.