Trust Center
How Unabated Products protects customer data. This page is for enterprise procurement, IT security, and anyone evaluating our security posture. Binding commitments live in the executed Master Services Agreement (MSA) and Data Processing Agreement (DPA).
Last updated: 2026-06-24
Compliance & Data Protection
Unabated Products does not currently hold its own SOC 2 attestation. Our service runs entirely on SOC 2 Type II and ISO 27001 certified infrastructure (Supabase, Netlify, GitHub), so the underlying compute, storage, and network controls are independently audited. The data-handling, encryption, and access commitments below describe how we operate on top of that infrastructure.
GDPR
Data Processing Agreement available on request; standard SCCs included.
CCPA
California data subject requests honored within 45 days.
Data We Handle
- Customer-provided: name, work email, role/title, company name (optional), and in-product interaction transcripts.
- We do not collect or process payment card data (handled by Stripe), health data, biometric data, or children's data.
- Residency: all customer data is stored in US-East via Supabase (AWS us-east-1). No cross-region replication without a contractual amendment.
Architecture & Encryption
- Application: React + TypeScript SPA delivered via Netlify global CDN.
- Backend: Supabase managed Postgres + serverless edge functions.
- In transit: TLS 1.2+ (TLS 1.3 preferred) on all endpoints; HSTS enforced.
- At rest: AES-256 on Postgres volumes (Supabase platform), which maintains its own SOC 2 Type II report.
- Secrets: stored in Supabase Vault and Netlify environment variables; never committed to source control.
Access Controls
- Customer access: email-based authentication with JWT session tokens (Supabase Auth). Optional SAML SSO on enterprise tier.
- Internal access: all production access requires MFA, with quarterly access reviews. Service-role keys are scoped to specific edge functions.
- Row Level Security: Postgres RLS policies enforce per-tenant isolation. Customers cannot access another tenant's data even with valid credentials.
Monitoring & Incident Response
- Application logs: a production-safe logger sanitizes PII before write; debug logs are suppressed in production builds.
- Incident response: documented IR plan with customer notification within 72 hours of a confirmed material incident (consistent with GDPR Art. 33).
- Security contact: security@unabatedproducts.com (one business-day response SLA).
Backup & Continuity
- Backups: daily automated Postgres backups via Supabase; point-in-time recovery enabled.
- Retention: 7 days minimum on standard tier; 30 days on enterprise tier.
- RTO: 4 hours (target). RPO: 24 hours (daily backup) or 1 minute (PITR).
- Disaster recovery: multi-AZ Postgres failover handled by the Supabase platform.
Subprocessors
We use the following subprocessors to deliver our services. Each is reviewed annually for certification status, data residency, and breach-notification SLAs. We provide 30 days' advance notice of new subprocessors, with a right to object per the DPA.
| Subprocessor | Purpose | Location | Certification |
|---|---|---|---|
| Supabase, Inc. | Database, auth, edge functions | US (AWS us-east-1) | SOC 2 Type II |
| Netlify, Inc. | Static hosting, CDN | Global (edge POPs) | SOC 2 Type II |
| Resend | Transactional email | US | SOC 2 Type II |
| GitHub, Inc. | Source code management | US | SOC 2 Type II, ISO 27001 |
| Anthropic, PBC | AI coaching model (Claude): learner responses sent for inference; no training on inputs/outputs, deleted within 30 days | US | SOC 2 Type II |
| Stripe, Inc. (planned) | Payments | US / EU | PCI DSS Level 1, SOC 2 |
Secure Development
- All code changes require pull-request review before merging to
main. - Dependency vulnerability scanning on every build (npm audit + Dependabot).
- Production deploys only from
mainvia CI; no direct manual deploys. - Third-party penetration testing (starting 2026 Q3).
Customer Rights & Data Portability
- Export: customers can export their data in JSON/CSV via the in-product UI or by request.
- Deletion: account deletion removes all customer data within 30 days; backups purge within an additional 90 days.
- Subprocessor changes: 30 days' advance notice; right to object per the DPA.
Questions?
Security & compliance: security@unabatedproducts.com
Pre-sales technical review: sales@unabatedproducts.com
Privacy / data subject requests: privacy@unabatedproducts.com