Multi-vendor · Security

A rival's buying contacts are not your data

When a hall holds kitchens from different businesses, the obvious thing to keep apart is the money. The less obvious one is the supplier list — who they buy from, at what price, and the email address an order goes to.


A food hall is not one business. Ten kitchens under one roof can be ten companies, and two of them can be competitors who happen to share a landlord and a set of toilets. Everybody understands that their takings are their own. Fewer people think about the purchasing screen.

What is actually on it

The screen that tells a manager what to order shows, for each supplier: the name, the products bought from them, the price paid for each one, the minimum order, the delivery days and the cut-off time. Next to that sits the address an order is sent to — an ordering email, a general email, a phone number.

Read that list again as a competitor. The prices alone tell you their margin on every dish you both sell. The delivery days tell you when their fridge is empty. And the ordering address is the single most useful line: it is who to approach if you want the same terms, or better ones.

Two lists, not one

We were scoping that screen properly this week and found the interesting part: there are two things to fence, not one, and they leak independently.

The obvious one is the product list — flour, cups, whatever each business buys. The second is the supplier list itself. It is tempting to think the second takes care of itself: if you only show suppliers who have products in the list, and the product list is scoped, then no outside supplier can appear.

That reasoning holds right up until a product points at somebody else's supplier. It happens: a spreadsheet import sets a supplier reference by name, two businesses use the same wholesaler, somebody duplicates a product row to save typing. The link between a product and a supplier is a field anybody's import can write, and it does not respect company boundaries by itself.

So the two fences protect different things. Scope the products only, and a rival's supplier can surface underneath one of your own products. Scope the suppliers only, and a rival's product can surface underneath one of your own suppliers. You need both, and testing either one alone will tell you everything is fine, because in the tidy case each hides the other's absence.

Nothing had leaked

Worth saying plainly, because a post like this reads like a confession. On our live database every product and every supplier belongs to the platform rather than to a tenant company, so every reader was already seeing the same set. The fix changes what would happen the day a hall onboards two rival businesses with their own catalogues, which is a day we would like to have arrived before the fence rather than after.

What to ask your own supplier of software

If you run a hall, or you are in one, the question is not "is it secure". Nobody answers that usefully. Ask instead: which screens show data that belongs to a specific business, and what decides which business a row belongs to? A good answer names a field, and names the place the check happens. A vague answer usually means the check happens in whichever screens somebody remembered.

And ask specifically about the purchasing side. Sales are guarded by everybody; buying rarely is, and buying is where the margin lives.


Try it on tonight’s service.

Nothing to install, no card. Not better by the weekend? Close the tab.