Defense in depth

Your equity data, protected at every layer.

We hold the most sensitive data a public company has — insider holdings, grant terms, compensation. Here is exactly how we protect it.

Encryption everywhere

Data is encrypted at rest with AES-256 and in transit with TLS 1.3. API keys and webhook secrets are stored encrypted (AES-GCM), never in cleartext.

Multi-tenant isolation

Tenant isolation is enforced in the database with PostgreSQL row-level security (RLS) and SECURITY DEFINER helpers — not just in application code.

Audit-ready controls, honestly stated

We are not yet SOC 2 certified and will not claim otherwise. Our controls — tenant isolation, encrypted secrets, immutable audit trail — are built to the Trust Services Criteria, and we will publish the report when we have one.

Continuous scanning

Automated dependency and secret scanning runs in CI on every commit, and every deploy is verified before release. Independent penetration testing is scheduled as we scale.

Incident response

A documented incident-response runbook with defined severities and a public status page. See our security policy for the full commitment.

Subprocessors

The third parties that process data on our behalf. Last updated 2026-05-28.

SupabaseManaged PostgreSQL database, auth, and object storage
VercelApplication hosting, edge network, and deployment
ResendTransactional email delivery
SentryError monitoring (enabled only when a DSN is configured)

Report a vulnerability

We operate a 90-day responsible-disclosure policy. Email security@unfoldingvalues.com and we will acknowledge within 2 business days.

Read our full security policy →