Bacon & Co. — est. 1925

Section 8 · Required Presentation Section 05

Platform Capabilities

Mobile, security, permissions, integrations, and the engineering resource behind all of it.

The platform is built and maintained in house. A change Pilot needs is something we decide, not something we request.

Our ordering platform supports high volumes of traffic and transactions simultaneously. The cloud-hosted environment scales elastically with demand, which is what keeps performance steady through the events that actually stress a company store — a program launch, a seasonal spike, a company-wide initiative.

We employ internal technical resources, including a dedicated software engineering team, supporting integration, reporting, platform development and evolving customer requirements.

B2B functionality, as it runs today
RequirementWhat it doesStatus
Per-user accountsMagic link, one-time code or password, held to Pilot's email domainsOperational
Role-based accessShopper, user, regional admin, store admin, organization adminOperational
Manager hierarchyEach person's approver, held on the record and used for routingOperational
Bulk employee importPeople, roles and managers loaded from a fileOperational
Role-based catalogsWhich pages and which products a role may seeOperational
Access codesA catalog behind a code that is never published to the browserOperational
Order approvalEvery order, or only the ones a policy catchesOperational
Approval policyOver an amount, a named payment method, a named buyer, or any custom buildOperational
Approval by emailA one-time link, so an approver who never signs in lands in the same recordOperational
Allowances and budgetsCredit granted per person, reserved at checkout, released if the order is refusedOperational
Payroll deductionCheckout with no card; the organization is billed and deducts from payOperational
Purchase ordersPO number captured at checkout, carried through to the invoiceOperational
Company-paid orderingThe employee sees $0; the real price sits against the organizationOperational
Card paymentAuthorized at checkout, captured on approval, card data never held by usOperational
Payment method accessWhich people may pick which methodOperational
Cost center captureCustom fields answered per order, or held once against the personOperational
Ship-to address bookCorporate addresses, scoped by who may use themOperational
Live inventoryStock read from the ERP, with a restock estimate rather than a hidden sizeOperational
Order trackingCarrier and number per line, pushed as each transfer is validatedOperational
Partial shipmentsEach line carries its own fulfillment stateOperational
Decoration libraryApproved logos held against the store, not retyped per orderOperational
PersonalizationNames, numbers and custom text captured on the lineOperational
PromotionsCodes with their own redemption limitsOperational
ReportingStore totals, the same money by item and by buyer, and an inventory positionOperational
ExportsExcel and PDF, from the page showing the figuresOperational
Support impersonationAn administrator can act as a buyer to reproduce a problemOperational
Audit logEvery administrative change, with the person who made itOperational
Multi-store, one loginOne account spanning every Pilot store, present and futureOperational
ERP integrationSigned publishes and order pushes, retried until they landOperational

Integration

  • API integrations.
  • EDI integrations.
  • Support for EPS integrations.
  • Support for Pilot-required integrations.
  • Secure ordering environments.
  • Administrative user controls and approval workflows.

We support both API and EDI connections to exchange order, inventory, shipping and invoicing information, and can support the integrations Pilot requires.

New employee

Integrate Pilot's HR management systems directly with Storefront and a new employee is onboarded the moment they are entered there — with their permissions and their user attributes already set, so their first sign-in shows the right catalog and charges the right budget.

Order notifications

Automated email at order confirmation, at shipment, and with tracking. An employee should not have to ask where an order is.

Continuous investment

We update and implement new technology continuously rather than holding a platform still between contracts. The engineering is in house, so an improvement is a decision we make.

Security

We build on infrastructure that is independently audited, so Pilot's security review does not come down to taking our word for it.

The providers hosting this platform and its data hold SOC 2 Type II attestations and ISO 27001 certification, renewed annually by third-party auditors, and run GDPR and CCPA compliance programs. Their audit reports are available to Pilot under NDA on request.

  • Encryption in transit and at rest, as the default rather than a setting.
  • Isolation enforced in the database itself. Every row carries the store it belongs to, and a query that does not match returns nothing — not fewer rows, none. One store cannot read another's orders, and neither can anyone without a server-side credential.
  • Card data never reaches our systems. Payment runs through a PCI DSS Level 1 gateway; we hold a token, not a number.
  • Credentials never reach our ERP. Registration, sessions and password policy sit with an audited identity provider, which takes both out of our audit scope.
  • Signed, time-limited requests between the store and the ERP, with a replay window measured in minutes.
  • Administrative actions are logged against the person who took them.
  • DDoS mitigation and a managed web application firewall at the edge.
  • Point-in-time database recovery, so a bad hour is recoverable rather than a bad day.
What Pilot can ask us for

Security questionnaires, the providers' current audit reports, penetration test summaries and a data flow diagram for the Pilot program. We would rather answer these during evaluation than at implementation.