Trust Center

Trust & Security

How we protect your data, the controls behind our platform, and exactly where we stand on the path to formal certification.

Compliance status

Where we stand

We're transparent about our posture — including what's still in progress. Live status is always current on our trust center.

In preparation

SOC 2

Implementing and documenting the security, availability, and confidentiality controls required for a SOC 2 examination.

Aligned

GDPR

EU data-subject rights are honored — access, rectification, erasure, and portability — with lawful processing and clear consent.

Aligned

CCPA / CPRA

California residents can access and delete their personal information and opt out of its sale or sharing.

Status reflects our internal readiness, not a completed third-party audit. Our SOC 2 examination is in progress; we do not claim to be certified.

Security practices

How we protect your data

Security is built into how we design, ship, and operate every system — not bolted on afterward.

Infrastructure & hosting

Workloads run on a GitOps-managed Kubernetes platform with network segmentation, infrastructure defined as code, and least-privilege workload identities in place of long-lived credentials.

Application security

Authentication is built on OAuth 2.0 with server-side session invalidation and CSRF protection. Secrets are encrypted, and dependencies are continuously scanned for known vulnerabilities.

Data protection

Data is encrypted in transit with TLS and at rest, with additional field-level encryption for sensitive values. Object storage is provider-agnostic and access-scoped per bucket.

Access control

Access follows the principle of least privilege with role-based permissions, and sign-in supports passwordless and multi-factor authentication for administrative accounts.

Monitoring & response

Errors and performance are monitored centrally, sensitive actions are audit-logged, and policy-as-code admission controls enforce guardrails across the cluster.

Vendors & subprocessors

We rely on a vetted set of subprocessors for infrastructure, payments, and communications. The full, current list is maintained in our trust center.

See the full details

Our live trust center hosts the complete control catalog, policies, and subprocessor list — and lets you request documentation under NDA.

Trust & Security | Corey Alan Consulting