Security and access
Security and access at ROI-AI
ROI-AI connects to two systems in your environment: your ERP, and one mailbox you designate for chargeback correspondence. What Roy can read and write in each is enumerated on this page, every credential is one you issue and can revoke without our involvement, and nothing is filed with a retailer without a release step you control.
This page is written to be forwarded. If you are the person who has to approve ROI-AI, it should tell you everything you need without a call. If something is missing, ask your ROI-AI contact and we will answer it in writing.
Last reviewed . Claims on this page are verified against our systems, not aspirational.
What ROI-AI can and cannot access
ROI-AI connects to two systems in your environment, your ERP and a mailbox you designate, and this table lists exactly what Roy can see and do in each and what it cannot.
Scroll the table sideways to see all five columns.
| System | What Roy reads | What Roy can write | What Roy cannot access | How it is granted |
|---|---|---|---|---|
| Your ERP | A named set of records a dispute needs: chargebacks and chargeback detail, invoices and invoice detail, purchase orders, pick tickets and packing detail, shipments, style and size master data, and customer master records. | Chargeback records only — creating the case and recording its outcome — plus purchase orders for customers who buy order entry. No other part of your ERP is writable, and there is no delete path. Bounded by the permissions your IT team grants the login. | Any module the dispute work does not require. No general or ad-hoc access to your database, and no access to your wider network, file shares, or workstations. | A database login your IT team creates, with the permissions your IT team chooses to grant. Revoke the login and our access ends. |
| One mailbox you nominate | Chargeback correspondence and its attachments in the single mailbox you designate for this work. | Dispute correspondence sent from the address you choose, and draft messages in that same mailbox. | Any other mailbox, and no calendar, file, or Teams content. | An application registration in your own Microsoft tenant that your administrator consents to, and can revoke at any time. |
| Retailer vendor portals | Your own chargeback and deduction records, as your vendor account already exposes them. | Filing a dispute, for those retailers where you have enabled it. Retrieval only everywhere else. | Anything outside your own vendor account on that retailer's portal. | A vendor-portal login you provide and control, revocable by you at any time. |
What ROI-AI never touches
- Bank accounts, routing numbers, ACH or wire details, and payment initiation of any kind
- Payroll, HR, and employee records
- Credit card data
- General access to your network, file shares, or workstations
- Any ERP module beyond the tables the dispute work requires
ROI-AI moves documents and dispute correspondence. It never moves money. Retailer-issued remittance advice and check and deduction detail are used as evidence only; no payment instruction is ever issued from them.
How the connection is constrained
Access is granted through credentials you create and control, scoped to the data Roy needs to work a chargeback, and the outer boundary on what Roy can write is the permission set your IT team grants the login.
What Roy reads in your ERP
Roy queries a defined set of ERP tables for the records a dispute needs: chargebacks and chargeback detail, invoices and invoice detail, purchase orders, pick tickets and packing detail, shipments, style and size master data, and customer master records. It does not browse your ERP; every query is scoped to a named table set.
What Roy writes, and only with your permission
ROI-AI's ERP writes are limited to the chargeback records the dispute work touches, meaning creating the case in your ERP and recording its outcome, plus purchase orders for customers who buy order entry. Nothing else in your ERP is writable, and there is no delete path in any of these functions. The outer boundary is the permission set your IT team grants the login: if you want no writes at all, scope the login to read-only and none of the above can write.
We state this plainly because a reviewer who discovers an undisclosed write path is right to distrust everything else on the page.
Scoping the login is your call
We work from the credentials and permissions your IT team chooses to grant. If you want ROI-AI limited to SELECT on a named table set, or to a dedicated set of views, we will work within that grant. Customers have done both.
How connections are made
Each customer's ERP connection is a separate, independently configured connection record. ROI-AI connects out to the endpoint your IT team specifies; we do not ask you to open your ERP to the public internet, and we do not install anything on your network beyond what an agreed integration requires.
How credentials are held
ERP and portal credentials are held in AWS Secrets Manager or encrypted at rest with envelope encryption, are referenced by name rather than embedded in code or configuration, and are scoped to your organization alone. No credential is shared across customers, and revoking the login you gave us cuts our access immediately.
Your mailbox
ROI-AI connects to a single mailbox that you designate for chargeback correspondence, using an application registration in your own Microsoft tenant that your admin consents to and can revoke at any time. We ask your IT team to apply a Microsoft Exchange application access policy so that the registration can reach only that one mailbox, even though the permission is tenant-scoped by design. ROI-AI reads chargeback correspondence and attachments from that mailbox and sends dispute correspondence from the address you choose. It does not touch any other mailbox, calendar, file, or Teams content.
The Exchange application access policy is applied by your own administrator, so it is a control you hold and can verify, not one you have to take our word for.
Retailer portals
Where a retailer requires portal filing, ROI-AI uses a vendor-portal login that you provide and control. It is used to retrieve your chargeback and deduction records and, for retailers where you have enabled it, to file the dispute. The credential is held as a reference in AWS Secrets Manager or encrypted at rest, is revocable by you at any time, and every portal login is recorded.
Your documents
Chargeback notices, bills of lading, invoices, packing lists, and the dispute packets Roy assembles are stored in Amazon S3 in our own AWS account, encrypted at rest with AES-256 and with public access blocked at the bucket level. Access is over TLS. Where a document is shown in the portal, it is served through a short-lived signed link rather than a public URL.
See our privacy policy for the encryption and data-handling terms of record.
Separation between customers
Each account is its own organization. Your identity and your organization are established from your verified sign-in, not from anything a browser can set, so a request cannot be redirected at another customer's data by tampering with it. Access within your organization is role-based, and we hold automated tests that specifically assert one organization cannot read another's cases.
Does Roy train on your data
No model is fine-tuned on your data, nothing is uploaded into a model provider's file store, and your data is not pooled with any other customer's.
If you need this as a contractual commitment rather than a description of how the system is built, we will put it in writing in a data processing agreement.
Where your data goes
Your cases and documents are stored under your own organization, and the organization a request acts on is established from your verified sign-in rather than from anything the request itself can set.
Your documents and records stay in our AWS environment. When Roy reasons over a case, the specific content needed for that step is sent over an encrypted connection to a hosted large-language-model API and the response comes back. Nothing is uploaded into a model provider's file store, no model is fine-tuned on your data, and your data is not pooled with any other customer's. Case records and Roy's working transcripts are stored in our own database, not the model provider's.
Categories of third party we rely on
- Cloud hosting and storage
- Runs the application and stores your documents and case records, encrypted at rest.
- Identity and authentication
- Verifies who is signing in to your organization's account.
- Hosted large-language-model API
- Performs the reasoning step on the specific case content Roy sends for that step.
- Email transport
- Carries dispute correspondence to and from the mailbox you nominate.
We list categories and purposes rather than vendor names. If your review requires the specific providers, ask your ROI-AI contact and we will supply them in writing.
Nothing reaches a retailer without a release step
Auto-submission is off by default for every reason code, and turning it on for a given reason code is a deliberate configuration change that you make and can reverse at any time.
Auto-submission is off by default, for every customer and every deduction reason code. Roy assembles the dispute and the evidence packet, and it is released for filing only after a review step. Whether a given reason code is ever released automatically is a setting you turn on deliberately, reason code by reason code, and you can turn it back off. Roy is not a fully autonomous filer, and we do not describe it as one.
More on what Roy does and how it works: the Roy platform page.
What we ask of your IT team
Setup asks your IT team for two things, a scoped credential to your ERP and access to one designated mailbox, and this section lists each request, why it is needed, and what it does not include.
A database login to your ERP, scoped how you choose
Why: So Roy can read the invoices, purchase orders, shipment records, and chargeback detail that a dispute has to cite.
What it does not include: No administrator rights, no access to modules the dispute work does not use, and no access to the host beyond the database endpoint.
Access to one mailbox you designate for chargeback correspondence
Why: So Roy can pick up retailer chargeback notices and their attachments, and send the dispute from an address you choose.
What it does not include: No other mailbox, no calendar, no files, no Teams. We ask you to apply an Exchange application access policy that pins the registration to that single mailbox.
A vendor-portal login, only for retailers that require portal filing
Why: So Roy can retrieve your deduction records and, where you enable it, file the dispute in the retailer's portal.
What it does not include: Nothing beyond your own vendor account. Not needed at all for retailers handled over email.
Certifications: what we hold and what we do not
ROI-AI does not hold SOC 2, ISO 27001, HIPAA, or PCI DSS attestations, and we will not imply otherwise.
ROI-AI does not currently hold SOC 2, ISO 27001, HIPAA, or PCI DSS certification, and we will not imply otherwise. We are happy to complete your security questionnaire, walk your IT team through our architecture, and sign a data processing agreement.
We also make no uptime or availability commitment on this page, because we do not have a measured service level to quote you. Any commitment we do make is contractual and lives in our master services agreement.
A vendor with no attestations should be assessed on what it actually does and on who it is. The controls above are the first half of that; who we are is the second.
How you keep control, and how you revoke access
Every credential you give us, you can revoke. Revoking it cuts our access immediately, with no dependency on us.
- Disable the database login your IT team issued. ERP reads stop at once.
- Revoke the application registration's consent in your Microsoft tenant, or remove it from the Exchange application access policy. Mailbox access stops.
- Change or disable the vendor-portal login you provided. Portal access stops.
- Turn off auto-submission for any reason code where you enabled it, at any time, without contacting us.
None of these steps requires our cooperation or a support ticket. What happens to your data after termination is governed by our master services agreement and privacy policy; ask your ROI-AI contact and we will confirm the process in writing for your records.
Common questions
The questions reviewers ask most often, answered directly.
- What systems does ROI-AI connect to?
- Two systems in your environment, plus retailer portals where a retailer requires portal filing: your ERP, and a single mailbox you designate for chargeback correspondence. Nothing else.
- Can ROI-AI change or delete data in our ERP?
- ROI-AI's ERP writes are limited to the chargeback records the dispute work touches, meaning creating the case in your ERP and recording its outcome, plus purchase orders for customers who buy order entry. Nothing else in your ERP is writable, and there is no delete path in any of these functions. The outer boundary is the permission set your IT team grants the login: if you want no writes at all, scope the login to read-only and none of the above can write.
- Does Roy train on our data?
- No model is fine-tuned on your data, nothing is uploaded into a model provider's file store, and your data is not pooled with any other customer's. Case records and Roy's working transcripts are stored in our own database, not the model provider's.
- Does anything get sent to a retailer without our approval?
- No. Auto-submission is off by default, for every customer and every deduction reason code. Roy assembles the dispute and the evidence packet, and it is released for filing only after a review step.
- Is ROI-AI SOC 2 certified?
- No. ROI-AI does not currently hold SOC 2, ISO 27001, HIPAA, or PCI DSS certification, and we will not imply otherwise. We are happy to complete your security questionnaire, walk your IT team through our architecture, and sign a data processing agreement.
- How do we revoke ROI-AI's access?
- Disable the database login your IT team issued, revoke the application registration's consent in your Microsoft tenant, and change the vendor-portal login you provided. Each takes effect immediately and none of them depends on us.
The owner packet
The forwardable summary of this page is available as a PDF, so whoever has to approve ROI-AI can review it without visiting the site or taking a call.
The packet contains the same access-scope matrix, the same constraints, and the same certification statement you have just read. It adds nothing that is not on this page.
Last reviewed .