Skip to content
Narell

Narell

Controls around the transaction

Narell’s implemented controls separate dealer data, restrict buyer and staff access and retain the evidence behind transaction decisions. The public deployment is a synthetic sandbox. The controls described here do not constitute a certification or acceptance of live sales.

Access follows the transaction and the role

Buyer and staff authentication are separate. Buyers can access their own purchases and documents. Staff access requires a current session, MFA proof for that session, active dealer membership and the permission needed for the action.

Tenant scoping and PostgreSQL row-level security provide separate layers of data isolation. Application database roles are separate from migration privileges. A dealer hostname or a submitted identifier is not permission to access a record.

Documents and accepted terms are retained

Accepted prices, parties, terms and document versions stay attached to the transaction. Original PDF bytes and hashes are retained; downloading a document does not regenerate an accepted contract. Document routes authorise access and use private caching policies.

Corrections create a new version or an explicit corrective record. Financial and operational actions retain an audit history for authorised staff.

Critical decisions are checked on the server

Database constraints prevent two active allocations for the same canonical vehicle. Contracted allocations are not released simply because a browser session or payment deadline expires. Critical commands use guarded transitions and retry controls.

Accountants record payment evidence. Specified corrections and approvals require supervisory permissions and an independent person. The server checks release requirements again when staff release or hand over a vehicle.

Provider failures remain visible

Separate worker execution tracks provider operations. Unknown signing, identity or email outcomes remain subject to review rather than being treated as success. Synthetic adapters are isolated from live-provider paths and cannot become a fallback for a production outage.

What still needs production acceptance?

Live provider acceptance, complete retention and encryption assurance, a measured recovery drill, secure supporting-evidence handling and operational procedures remain release requirements. Configured backups alone are not proof of recoverability. Narell makes no ISO 27001, SOC 2, PCI or GDPR certification claim.

Review provider implementation status and website privacy information. Use the Narell contact route to discuss technical due diligence. Do not include personal transaction data or credentials in an initial enquiry.

Contact Narell →