Vendor Security Packet
Last updated: March 2026
This page consolidates all security, compliance, and data protection documentation for enterprise procurement and security review teams. Everything a vendor security reviewer needs is linked from here.
Our Security Posture (Honest Summary)
What we have:
- SOC 2-certified infrastructure providers
- TLS 1.2+ encryption, AES-256 at rest
- OAuth 2.0 via GitHub/Google
- RBAC with 4 org roles + superadmin
- Tenant isolation at query level (49 routes)
- Audit logging, Sentry error monitoring
- Rate limiting (Redis, fail-open)
- Deterministic compliance engines
- GDPR-aligned DPA with SCCs
What we don't have yet:
- SOC 2 Type II audit (in progress)
- ISO 27001 certification
- Third-party penetration testing
- SAML-based SSO
- MFA enforcement at app level
- Multi-region deployment
- Staging environment
- Formal DR drill testing
Core Documents
System Architecture
Platform architecture, data flows, trust boundaries, encryption zones, and tenant isolation boundaries.
Access Controls
Authentication methods, role hierarchy, organization membership, API key management, and 3-layer authorization gates.
Data Handling Policy
What data we collect, store, and delete across every product surface. Retention periods and encryption details.
Data Processing Agreement
GDPR Article 28 compliant DPA. Definitions, scope, sub-processor management, SCCs, and termination terms.
Subprocessors
Complete list of third-party service providers. 9 subprocessors across infrastructure, payment, email, and security.
Incident Response Plan
Severity classification, 6-phase response process, customer notification, and regulatory obligations.
Additional Resources
Security Practices
Technical security controls detail
Compliance Matrix
Cross-framework control mapping
Change Management
SDLC, CI/CD, code review
Business Continuity
BCP/DR, RTO/RPO, backup strategy
Vulnerability Disclosure
Responsible disclosure policy
Privacy Policy
Data collection and usage
Terms of Service
Service terms and conditions
SLA
Service level agreement
Questions?
Our security team is available to answer detailed questions about our infrastructure, compliance posture, and security practices.