Source documents encrypted at rest. Row-level security on every database table. Lender access only with explicit per-deal authorization. We do not sell, share, or aggregate deal data.
Source documents and database fields encrypted at rest in Supabase managed Postgres. Storage objects encrypted with server-side keys rotated by Supabase.
Every request between browser and server, server and Supabase, server and Anthropic, server and Resend runs over TLS 1.3 with HSTS preload on acren.ai.
Supabase project hosted in us-east-1 (AWS Northern Virginia). Vercel application served from global edge with US-East primary. No data leaves United States soil.
Supabase Auth with bcrypt-hashed passwords, Google OAuth, Microsoft OAuth, and email magic link. Session tokens are short-lived; refresh tokens are revocable from settings.
All vendors named below are bound by data-processing agreements. We notify by email at least fourteen days before adding, removing, or materially changing a subprocessor.
| Vendor | Purpose | Data class | Region | DPA |
|---|---|---|---|---|
| Supabase | Database, storage, authentication | Account · Deal · Documents | US-East-1 | v2024.06 |
| Vercel | Application runtime, edge cache | No persisted user data | Global edge, US primary | v2024.04 |
| Anthropic | Document extraction and scoring | Source documents (transient) | United States | v2025.01 |
| Resend | Outbound email delivery | Email + recipient name | United States | v2024.08 |
| Sentry | Application error capture | Stack traces (PII scrubbed) | US Cloud | v2024.11 |
| PostHog | Page views, click events, errors | Anonymized usage events | US Cloud | v2024.10 |
| Stripe | Payment processing | Card data, billing address | United States | v2024.05 |
| Data class | Active retention | After deletion request | Backup window |
|---|---|---|---|
| Source documents | While account active | 30-day soft delete, then permanent purge | 14-day point-in-time recovery |
| Extracted financial fields | While account active | 30-day soft delete, then permanent purge | 14-day point-in-time recovery |
| Account data | While account active | 30-day soft delete, then permanent purge | 14-day point-in-time recovery |
| Authentication tokens | 1 hour (session), 30 days (refresh) | Immediate revocation | None |
| Email logs | 30 days | Purged on schedule | None |
| Analytics events | 12 months | 30-day purge of identified events | None |
| Error traces | 90 days | Purged on schedule | None |
Honest about what's implemented versus what's on the roadmap. We don't claim certifications we don't have.
Security disclosures, vulnerability reports, or data handling questions: security@acren.ai. We acknowledge within one business day, prioritize within five, and patch verified issues on a rolling cadence with credit attribution to the reporter.
PGP key + security.txt available at acren.ai/.well-known/security.txt