We use cookies

    We use cookies to improve your experience and analyze site usage. You can choose which cookies to accept.

    Trust Center

    How Unabated Products protects customer data. This page is for enterprise procurement, IT security, and anyone evaluating our security posture. Binding commitments live in the executed Master Services Agreement (MSA) and Data Processing Agreement (DPA).

    Last updated: 2026-06-24

    Compliance & Data Protection

    Unabated Products does not currently hold its own SOC 2 attestation. Our service runs entirely on SOC 2 Type II and ISO 27001 certified infrastructure (Supabase, Netlify, GitHub), so the underlying compute, storage, and network controls are independently audited. The data-handling, encryption, and access commitments below describe how we operate on top of that infrastructure.

    GDPR

    Data Processing Agreement available on request; standard SCCs included.

    Certified

    CCPA

    California data subject requests honored within 45 days.

    Certified

    Data We Handle

    • Customer-provided: name, work email, role/title, company name (optional), and in-product interaction transcripts.
    • We do not collect or process payment card data (handled by Stripe), health data, biometric data, or children's data.
    • Residency: all customer data is stored in US-East via Supabase (AWS us-east-1). No cross-region replication without a contractual amendment.

    Architecture & Encryption

    • Application: React + TypeScript SPA delivered via Netlify global CDN.
    • Backend: Supabase managed Postgres + serverless edge functions.
    • In transit: TLS 1.2+ (TLS 1.3 preferred) on all endpoints; HSTS enforced.
    • At rest: AES-256 on Postgres volumes (Supabase platform), which maintains its own SOC 2 Type II report.
    • Secrets: stored in Supabase Vault and Netlify environment variables; never committed to source control.

    Access Controls

    • Customer access: email-based authentication with JWT session tokens (Supabase Auth). Optional SAML SSO on enterprise tier.
    • Internal access: all production access requires MFA, with quarterly access reviews. Service-role keys are scoped to specific edge functions.
    • Row Level Security: Postgres RLS policies enforce per-tenant isolation. Customers cannot access another tenant's data even with valid credentials.

    Monitoring & Incident Response

    • Application logs: a production-safe logger sanitizes PII before write; debug logs are suppressed in production builds.
    • Incident response: documented IR plan with customer notification within 72 hours of a confirmed material incident (consistent with GDPR Art. 33).
    • Security contact: security@unabatedproducts.com (one business-day response SLA).

    Backup & Continuity

    • Backups: daily automated Postgres backups via Supabase; point-in-time recovery enabled.
    • Retention: 7 days minimum on standard tier; 30 days on enterprise tier.
    • RTO: 4 hours (target). RPO: 24 hours (daily backup) or 1 minute (PITR).
    • Disaster recovery: multi-AZ Postgres failover handled by the Supabase platform.

    Subprocessors

    We use the following subprocessors to deliver our services. Each is reviewed annually for certification status, data residency, and breach-notification SLAs. We provide 30 days' advance notice of new subprocessors, with a right to object per the DPA.

    SubprocessorPurposeLocationCertification
    Supabase, Inc.Database, auth, edge functionsUS (AWS us-east-1)SOC 2 Type II
    Netlify, Inc.Static hosting, CDNGlobal (edge POPs)SOC 2 Type II
    ResendTransactional emailUSSOC 2 Type II
    GitHub, Inc.Source code managementUSSOC 2 Type II, ISO 27001
    Anthropic, PBCAI coaching model (Claude): learner responses sent for inference; no training on inputs/outputs, deleted within 30 daysUSSOC 2 Type II
    Stripe, Inc. (planned)PaymentsUS / EUPCI DSS Level 1, SOC 2

    Secure Development

    • All code changes require pull-request review before merging to main.
    • Dependency vulnerability scanning on every build (npm audit + Dependabot).
    • Production deploys only from main via CI; no direct manual deploys.
    • Third-party penetration testing (starting 2026 Q3).

    Customer Rights & Data Portability

    • Export: customers can export their data in JSON/CSV via the in-product UI or by request.
    • Deletion: account deletion removes all customer data within 30 days; backups purge within an additional 90 days.
    • Subprocessor changes: 30 days' advance notice; right to object per the DPA.

    Questions?

    Security & compliance: security@unabatedproducts.com

    Pre-sales technical review: sales@unabatedproducts.com

    Privacy / data subject requests: privacy@unabatedproducts.com

    This page reflects our current security posture and is updated as our compliance program matures.