Your data lives in your tenant.
We never sell it, share it, or train models on it. Anything automated we run is bounded to your tenant’s data and cannot reach across tenants.
Security & trust
We host your operations. We don’t own your business.
Compliance + integrations
No seals, no shields. The status is the signal — written out, kept current, and equal in weight to what is still in progress.
Data ownership
We never sell it, share it, or train models on it. Anything automated we run is bounded to your tenant’s data and cannot reach across tenants.
Your Stripe receives the payments. Your QuickBooks has the synced invoices. We help you connect them; we do not own them.
SOC 2 Type II is planned — the audit has not started yet. We disclose the status honestly — no marketing-flex on an audit we have not run.
Compliance posture
The rows we have not finished are listed with the same dignity as the ones we have. That is the point.
| Standard | Status | Notes |
|---|---|---|
| SOC 2 Type II | Planned | On our roadmap; audit not yet engaged. |
| PCI DSS | Via Stripe | Payments processed by Stripe (certified PCI-DSS Level 1). Card details never touch our servers. |
| GDPR | DSR portal | Customer-facing DSR submission. 30-day response. |
| CCPA | DSR portal | Customer-facing DSR submission. 45-day response. |
| HIPAA | Not in scope | We do not host PHI. Service shops do not need HIPAA. |
| ISO 27001 | Not yet | Will revisit at $5M ARR. |
On our roadmap; audit not yet engaged.
Payments processed by Stripe (certified PCI-DSS Level 1). Card details never touch our servers.
Customer-facing DSR submission. 30-day response.
Customer-facing DSR submission. 45-day response.
We do not host PHI. Service shops do not need HIPAA.
Will revisit at $5M ARR.
How we handle data
Encrypted at rest (AES-256) and in transit (TLS 1.3).
Daily encrypted backups; 30-day retention. Point-in-time recovery to any moment in the last 7 days.
Hosted on Supabase (database) and Vercel (web app). US-East-2 primary, US-West-2 backup.
Payments are securely processed by Stripe, a certified PCI-DSS Level 1 Service Provider — the highest level of payment-security compliance. Your card details are encrypted and sent directly to Stripe; they never touch our servers, and we never store your card number.
DSR portal
CCPA and GDPR data-subject-rights requests can be submitted by email. Anyone — your customers, your customers’ attorneys — can submit a request. We respond within the statutory timelines (30 days GDPR, 45 days CCPA per California and EU privacy law). A self-serve DSR portal lands ahead of GA.
Security FAQ
We will share the architecture diagram and an open Q&A with the engineering lead — ask us about our security roadmap.