Security

Built on infrastructure that's already been audited.

We don't ask you to trust a homegrown backend. What we build runs on the same hosting, auth, payments, and email providers that independently certified companies rely on.

How we handle access and data

  1. 01

    Encryption in transit and at rest

    Traffic is encrypted with TLS in transit, and data at rest is encrypted by the infrastructure providers listed below.

  2. 02

    Scoped, least-privilege access

    We request only the access a given engagement requires — a scoped API key or a dedicated integration user, never standing admin access by default.

  3. 03

    NDA before discovery

    We're happy to sign a mutual NDA before any discovery call, so nothing about your process or systems needs to wait on paperwork later.

  4. 04

    No selling contact or usage data

    Data submitted through this site or shared during an engagement is used to deliver the work — not sold or shared with third parties.

Infrastructure partners

Certifications below are held by each named provider, not by us directly — verify current status on each provider's trust page before relying on it for your own compliance requirements.

ProviderRoleCertification
VercelApplication hostingSOC 2 Type II
StripePayments & billingPCI DSS Level 1, SOC 2 Type II
ClerkAuthenticationSOC 2 Type II
ResendTransactional emailSOC 2 Type II

Questions about a specific requirement?

If your engagement has specific compliance needs — HIPAA, a client DPA, a security questionnaire — tell us during the audit and we'll work through it before any build starts.

See also our Privacy Policy and Terms of Service.