Trust
Compliance & Data Practices
How we handle, protect, and process your data.
Data Handling
All user data is stored in a Supabase-managed PostgreSQL instance in the US-East-1 region. Credentials, lab completions, and billing information are stored in encrypted-at-rest databases.
Encryption
All data in transit is encrypted via TLS 1.2+. Database at rest uses AES-256. API keys and service credentials are stored as environment variables, never in source control.
Access Controls
Row-level security (RLS) is enforced at the database layer for all user-facing tables. Service role access is restricted to server-side API routes and scheduled Edge Functions.
Subprocessors
| Vendor | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, storage | US |
| Resend | Email delivery | US |
| Stripe | Payment processing | US |
| Vercel | Hosting, CDN | Global |
Credential Data
AIPSA credentials are publicly verifiable at aisecurity.llc/aipsa/verify/[id]. Credential records are retained indefinitely unless revocation is requested.
Contact
For data requests, deletion, or compliance questions: privacy@aisecurity.llc