FeaturesSecurityPricingDevelopersBlogStart Free

Trust Center

How we protect your deal.

Sifrsys is a virtual data room built for the most confidentiality-sensitive transactions. This page states our security posture plainly — what is in place today, and what is on the roadmap — with no claim we cannot back up.

For a deeper technical walk-through, see our security overview.

Compliance & certifications

AreaStatusDetail
SOC 2 Type IIReadiness in progressControls built and mapped; engagement not yet signed. Roadmap available on request.
Encryption at restIn placeAES-256 on all stored data (Supabase / AWS KMS).
Encryption in transitIn placeTLS 1.3 on all connections.
Tamper-evident audit logIn placeSHA-256 hash-chained, verified on a schedule.
AI data handlingIn placePermission-fenced at the database level; zero provider retention; never used for model training.
GDPR / DPADPA available on requestData Processing Agreement and SCCs available; not represented as a certification.
Penetration testPlannedIndependent test scheduled ahead of the SOC 2 engagement.

We do not display a certification badge until the corresponding engagement is complete.

Security architecture

  • Database-enforced isolation. Every tenant's data is separated by Row-Level Security in the database, not just in application code — so a bug in the app cannot cross the boundary.
  • Permission-fenced AI. The AI can only retrieve what the asking participant is authorized to see; the same database rules that protect documents protect the AI's answers.
  • Tamper-evident audit log. Every access and permission change is written to a SHA-256 hash-chained log whose integrity is verified on a schedule; tampering is detectable.
  • Forensic watermarking. Documents are stamped per viewer at access time, so a leak traces back to its source.
  • Zero training, zero provider retention. Your content is never used to train models and is not retained by our AI providers.

Subprocessors

We use the following third parties to operate the service. We provide advance notice of material changes to this list.

ProviderPurposeLocation
SupabaseDatabase, authentication, storageUnited States
VercelApplication hosting / CDNUnited States
HetznerDocument processing (transient)Germany (EU)
StripePayments (billing data only)United States
ResendTransactional emailUnited States
TwilioSMS / WhatsApp invitationsUnited States
AnthropicAI responses (zero retention, no training)United States
Voyage AIText embeddings (zero retention)United States
GoogleOAuth sign-inUnited States

To be notified of subprocessor changes, email security@sifrsys.com.

Availability

Sifrsys runs on managed, highly-available infrastructure. A public status page is being stood up; in the meantime, report any availability issue to security@sifrsys.com.

Request our security documentation

For your vendor review, we can share — under NDA where appropriate — our security whitepaper, subprocessor list, Data Processing Agreement, and completed security questionnaire (CAIQ / SIG). Email security@sifrsys.com and tell us what your team needs.

To report a vulnerability, see our disclosure policy.

Start Free