Trust

Security & Trust

We take data protection seriously — built for regulated industries that demand it.

Infrastructure & Hosting

Reg Alerts Pro is hosted on Vercel and Supabase — both SOC 2 Type II certified infrastructure providers. All data is encrypted in transit using TLS and encrypted at rest.

Data Isolation

Reg Alerts Pro uses a multi-tenant architecture that enforces strict per-organization data isolation. Every request is scoped and validated using Postgres row-level security (RLS) policies at the database layer, so one organization's data is never accessible to another.

Access Control

Access within an organization is governed by role-based access control, with distinct admin and member roles. Key account and data actions are audit logged.

Authentication

Authentication is handled via Supabase Auth using password-based login, with session state maintained through httpOnly cookies to protect against client-side token theft.

Payments

Card data never touches Reg Alerts Pro servers. All payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider — the highest level of certification available in the payments industry.

Data Retention & Deletion

Customers can request an export or deletion of their data at any time by contacting support. We will action verified requests promptly.

Sub-processors

We work with a small number of trusted sub-processors to deliver the service:

  • Supabase — database and authentication.
  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • Anthropic — AI-assisted analysis.
  • Vercel — application hosting.

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you believe you've found a security issue in Reg Alerts Pro, please email info@regalertspro.com with details so we can investigate. We ask that you do not publicly disclose any suspected vulnerability until we've had a chance to investigate and remediate it. We do not currently offer a paid bug bounty program.

Incident Response

We maintain an internal incident response process covering detection, containment, remediation, and customer notification. In the event of a security incident affecting customer data, we will notify affected customers without undue delay and in line with applicable legal requirements. Full incident response documentation is available on request under NDA for enterprise customers conducting vendor security review.

Our Approach to Compliance

Security is a continuous priority, not a checkbox. As we grow, we're committed to pursuing formal certifications such as SOC 2 Type II to further validate our security practices and give customers additional independent assurance.

Contact

Have a security question or want to report a concern? Email info@regalertspro.com — we're happy to help.

For a summary of our security practices, download our Security Overview.