Trust Center
Sifrsys is a virtual data room built for the most confidentiality-sensitive transactions. This page states our security posture plainly — what is in place today, and what is on the roadmap — with no claim we cannot back up.
For a deeper technical walk-through, see our security overview.
| Area | Status | Detail |
|---|---|---|
| SOC 2 Type II | Readiness in progress | Controls built and mapped; engagement not yet signed. Roadmap available on request. |
| Encryption at rest | In place | AES-256 on all stored data (Supabase / AWS KMS). |
| Encryption in transit | In place | TLS 1.3 on all connections. |
| Tamper-evident audit log | In place | SHA-256 hash-chained, verified on a schedule. |
| AI data handling | In place | Permission-fenced at the database level; zero provider retention; never used for model training. |
| GDPR / DPA | DPA available on request | Data Processing Agreement and SCCs available; not represented as a certification. |
| Penetration test | Planned | Independent test scheduled ahead of the SOC 2 engagement. |
We do not display a certification badge until the corresponding engagement is complete.
We use the following third parties to operate the service. We provide advance notice of material changes to this list.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | United States |
| Vercel | Application hosting / CDN | United States |
| Hetzner | Document processing (transient) | Germany (EU) |
| Stripe | Payments (billing data only) | United States |
| Resend | Transactional email | United States |
| Twilio | SMS / WhatsApp invitations | United States |
| Anthropic | AI responses (zero retention, no training) | United States |
| Voyage AI | Text embeddings (zero retention) | United States |
| OAuth sign-in | United States |
To be notified of subprocessor changes, email security@sifrsys.com.
Sifrsys runs on managed, highly-available infrastructure. A public status page is being stood up; in the meantime, report any availability issue to security@sifrsys.com.
For your vendor review, we can share — under NDA where appropriate — our security whitepaper, subprocessor list, Data Processing Agreement, and completed security questionnaire (CAIQ / SIG). Email security@sifrsys.com and tell us what your team needs.
To report a vulnerability, see our disclosure policy.