Security

How we protect Confidant.

We publish the security practices we actually run — not a certificate we have not earned yet.

Updated 2026-07-27

We are not certified yet

Confidant has not completed a SOC 2, ISO 27001, or similar third-party audit. We do not display SOC or ISO badges. When a school or partner requires attestation, we will pursue SOC 2 Type I first — and only then show proof. Until then, this page describes our current operational controls.

No SOC 2 or ISO badges are shown on this site.

Practices we run today

Honest controls — not marketing claims.

Encryption in transit and at rest

All production traffic uses TLS with HSTS. Application data is stored in Supabase (Postgres) with encryption at rest. Device API tokens are hashed and encrypted before storage.

Least-privilege access

Customer data is scoped by organization and role on the server. Platform admin routes require an admin role. Multi-factor authentication for admins is supported and can be enforced when enabled.

Privacy by design

We do not use cameras, microphones, facial recognition, or location tracking. We collect door open/close timestamps and the minimum data needed for alerts and activity history. Privacy mode pauses resident activity writes for staff views while device health can continue when allowed.

Web application hardening

API routes enforce session checks and rate limits where appropriate. Cron and webhook endpoints require secrets or signed payloads. Security headers (CSP, frame denial, nosniff) are applied on responses. Sensitive values are never committed to source control.

Trusted infrastructure vendors

Core hosting and data processing run on Supabase, Vercel, and Stripe. Full subprocessors are listed below and on our Privacy page. We do not sell customer data.

Retention and deletion

Door event retention is configurable by account owners (Enterprise compliance tools). Scheduled jobs delete aged event data per policy. Customers can request export or deletion.

Incident response

We maintain an internal incident response runbook covering detection, containment, customer notification, and post-incident review.

Subprocessors

Vendors that process data on our behalf. Details also appear on our Privacy page.

VendorPurposeDataPolicy
SupabaseDatabase, authentication, and file storageAccount, property, device, and activity dataView
VercelApplication hosting and edge deliveryRequest logs and application trafficView
StripePayments and subscriptionsBilling contact and payment metadataView
ResendTransactional and alert email deliveryEmail addresses and message content you authorizeView
Google AnalyticsOptional website analytics (only after cookie consent)Anonymized or pseudonymous usage metricsView

Report a vulnerability

If you believe you found a security issue, email us. Please include steps to reproduce and avoid accessing customer data beyond what is needed to demonstrate the issue. We will acknowledge responsible reports.

security@confidant365.com

Compliance roadmap

  1. 1Operate and document real security practices (this page).
  2. 2Keep Privacy, subprocessors, and cookie consent current.
  3. 3Enable admin MFA when the Auth plan supports it.
  4. 4Maintain internal runbooks for incidents, access reviews, and backup tests.
  5. 5Engage an auditor for SOC 2 Type I only when a school or partner requires it.
  6. 6Pursue SOC 2 Type II and/or ISO 27001 later if customers need continuous attestation — and only then display badges.
Security | Confidant