Your data security is our foundation
Enterprise-grade infrastructure on Google Cloud (europe-west1), encryption in transit and at rest, multi-tenant isolation via Row Level Security, and SOC2 Type I roadmap.
Encryption
TLS 1.3 in transit everywhere. AES-256 encryption at rest on all data (Supabase + Cloud Storage). Secrets managed in Google Secret Manager with 90-day rotation.
Infrastructure
Deployed on Google Cloud Run in europe-west1 (Belgium) for GDPR data-at-rest compliance. Serverless, auto-scaling, zero servers to maintain. Cloud Armor WAF in front of all APIs.
Compliance
GDPR by design, EU-only hosting, DPO available on request, documented processing register. SOC2 Type I roadmap launched, report available 6 months post-MVP.
Access control
PostgreSQL Row Level Security on all tables (isolation per clerk_id). MFA available for all accounts via Clerk. SOC2 audit logs for every sensitive action.
SOC2 Type I Roadmap
We are committed to a SOC2 Type I certification process. Identity, confidentiality, availability, and processing integrity controls are being implemented. Audit report expected within 6 months of MVP.
Specific security, DPA, or due diligence questions? Contact our team