Trust
Security & Trust
We take data protection seriously — built for regulated industries that demand it.
Infrastructure & Hosting
Reg Alerts Pro is hosted on Vercel and Supabase — both SOC 2 Type II certified infrastructure providers. All data is encrypted in transit using TLS and encrypted at rest.
Data Isolation
Reg Alerts Pro uses a multi-tenant architecture that enforces strict per-organization data isolation. Every request is scoped and validated using Postgres row-level security (RLS) policies at the database layer, so one organization's data is never accessible to another.
Access Control
Access within an organization is governed by role-based access control, with distinct admin and member roles. Key account and data actions are audit logged.
Authentication
Authentication is handled via Supabase Auth using password-based login, with session state maintained through httpOnly cookies to protect against client-side token theft.
Payments
Card data never touches Reg Alerts Pro servers. All payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider — the highest level of certification available in the payments industry.
Data Retention & Deletion
Customers can request an export or deletion of their data at any time by contacting support. We will action verified requests promptly.
Sub-processors
We work with a small number of trusted sub-processors to deliver the service:
- Supabase — database and authentication.
- Stripe — payment processing.
- Resend — transactional email delivery.
- Anthropic — AI-assisted analysis.
- Vercel — application hosting.
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you believe you've found a security issue in Reg Alerts Pro, please email info@regalertspro.com with details so we can investigate. We ask that you do not publicly disclose any suspected vulnerability until we've had a chance to investigate and remediate it. We do not currently offer a paid bug bounty program.
Incident Response
We maintain an internal incident response process covering detection, containment, remediation, and customer notification. In the event of a security incident affecting customer data, we will notify affected customers without undue delay and in line with applicable legal requirements. Full incident response documentation is available on request under NDA for enterprise customers conducting vendor security review.
Our Approach to Compliance
Security is a continuous priority, not a checkbox. As we grow, we're committed to pursuing formal certifications such as SOC 2 Type II to further validate our security practices and give customers additional independent assurance.
Contact
Have a security question or want to report a concern? Email info@regalertspro.com — we're happy to help.
For a summary of our security practices, download our Security Overview.