Skip to content
waputuGet started

Security and operational controls

Clear boundaries.
Traceable actions.

Security is part of how the workflow behaves: who can act, which facility they can act in, and what evidence survives afterward.

Separate customer environments

Verified registration provisions a dedicated database and application for the organization. The signup portal has its own identity context. A portal user is not automatically a customer-workspace user.

Role and facility authorization

Protected operations check the authenticated identity, role and facility grants on the server. Editing a URL or job identifier does not grant access to another facility.

Privileged MFA

Owners and administrators complete multi-factor authentication. Password recovery preserves enrolled MFA and does not reactivate disabled profiles.

Server-side credential handling

State credentials are submitted through the authorized connection flow and handled on the server. Service credentials are kept out of browser code. Support instructions prohibit sharing tokens, passwords and MFA secrets.

Durable state-write history

Each sublot child records an intent before the state request. Unknown outcomes stop for reconciliation. The recovery design avoids treating a timeout as proof of failure.

Immutable label snapshots

Saved label jobs preserve the released content and checksum. Reprints use the snapshot and record download events; they never repeat the split action.

Your part in the boundary

Use an authorized integration identity, protect credentials, assign the least privilege, remove departed staff, review source freshness and validate physical labels. Keep a lawful contingency process for external-system outages.

Review permissions →

Report a concern

Use the contact form with the affected workspace, safe description and time. Do not submit exploit payloads containing customer secrets or access another organization to prove an issue.

Report a security concern →

What this page does not claim

No SOC 2, ISO, government certification, perfect uptime or immunity from incidents is claimed. Contractual service levels and additional assurance documents require an explicit agreement.

Read privacy information →

Recover without making the incident larger.

A compromised credential and an uncertain inventory request are different incidents. Rotate credentials through the authorized process. For an unknown sublot result, preserve the original job and compare state evidence before resuming. Never create a replacement request simply to make an error disappear.

State availability, source accuracy and physical printer output are separate dependencies. Waputu checks what its software can verify and keeps the operator review visible for the rest.

Read the recovery procedure