What we do with your business data.
The documents your security and legal teams ask for, in one place, written plainly. Where something is still in progress, it says so.
Status for your own account, measured live, is on the Status page inside the portal.
Open your status pageData Processing Agreement
Available before signature, on request.
Security overview
Controls in place today, in plain language.
Security questionnaire
Send yours, or ask for ours.
Six commitments we can describe in a sentence.
Read first, write by approval
Connections read your systems. Anything that sends, pays or binds you stops for a person you name to approve it, and is logged.
A separate space for every client
Each client's records are isolated in the database itself, not only in application code. One client cannot read another's rows.
Sealed with your own key
Documents are encrypted with a key that belongs to your company alone, and credentials you give us are stored the same way and are never shown again.
Sign-in you control
Multi-factor sign-in is required for every member and enforced by the database. Single sign-on through your identity provider is available.
A complete record
Opens, downloads, approvals and changes to access are written by the system as they happen. Owners and admins can browse and export the trail.
Retention you set
You choose how long data is kept. When an engagement ends, data is deleted from production within 30 days, with a signed deletion certificate.
The full list of 17 controls, with what is still on the roadmap, is on the security page.
Where we are, stated honestly.
We have not started a SOC 2 audit and hold no SOC 2 report. This is the plan. We will update it as each step is actually begun and finished, and not before.
- Planned
SOC 2 Type I
Not started. We will not describe ourselves as compliant, or name a date, until the work is under contract with an auditor.
- Planned
SOC 2 Type II
Follows Type I. Not started.
- Planned
Independent penetration test
Not yet performed. We do not offer our own internal testing as a substitute for a third party's.
Who else touches your data.
| Subprocessor | Purpose | Data |
|---|---|---|
| Supabase | Database, sign-in and encrypted storage | Account records, tenant data, uploaded files |
| Fly.io | Application hosting | Requests to the portal and its APIs |
| Stripe | Billing and invoicing | Billing contacts and payment status |
| Resend | Transactional email | Names and work email addresses |
List derived from the platform's code on 2026-10-05.
Need a security review for procurement?
Send your questionnaire and a named contact. We answer in writing.