Enterprise transaction controls
SBCMI Store is structured to keep legal identity, payment, invoicing, tax, privacy and transaction evidence explicit. Live commerce remains blocked until the required production controls are configured.
Purchase controls
- International business-customer checkout
- 100% cleared payment before provisioning
- Recorded acceptance of Terms of Sale and Privacy Policy
- Business and tax profile captured before payment
- Order, payment, tax and invoice audit trail
Required production identity
- Official commercial registration number
- VAT registration number where applicable
- Registered business address
- Published customer-service email
- Approved privacy contact channel
These identifiers are intentionally not invented in the code. They must be populated from official corporate records before LIVE_COMMERCE_ENABLED=true.
Launch readiness
Set STORAGE_DRIVER=postgres and DATABASE_URL.
Configure official CR, VAT number, registered address and published support email from corporate records.
Final legal text must be approved before live commerce.
Production downloads must use private object storage and short-lived server-signed URLs.
Approved tax rules and customer-location evidence must drive the final transaction treatment.
Use merchant-issued production credentials and provider-verified webhooks.
Refund execution must use an authenticated provider adapter and verified provider status.
Provider settlements and the Saudi company bank account must be reconciled under an approved operating process.
Annual Assurance must use either approved recurring billing or explicit manual renewal.
Connect the applicable ZATCA-compliant electronic invoicing solution.
Final manual launch switch after every control is verified.
