Hosting + edge
LiveVercel (EU-hosted functions available). Database + auth on Supabase (EU region for EU workspaces on request). No customer data leaves the EU when the EU-residency flag is set.
Encryption in transit + at rest
LiveTLS 1.3 everywhere. Supabase enforces at-rest encryption via pgcrypto. Client-side fields (OAuth tokens, API keys) encrypted with AES-256 before insert.
Authentication
LivePassword + magic link via Supabase Auth. Rate-limit + brute-force protection at the edge. SSO via WorkOS (Okta, Azure AD, Google Workspace) for enterprise tenants.
Row-level security
LiveEvery tenant-scoped table enforces RLS. Workspace data is never joinable across tenants. Service-role key is server-only and never exposed client-side.
Audit trail export
LiveEvery Sophie decision (confirmations, action transitions, gate flips) is logged immutably to decision_records. Exportable via /api/admin/audit-trail-export.
Rate limiting + abuse guards
LivePer-IP + per-user rate limits on every Sophie turn + assessment submit. HMAC-signed webhooks with constant-time comparison. Certification quiz token enforces per-attempt choice shuffle.
Data retention + deletion
LiveSophie memory entries are workspace-scoped and deletable from /workspace/[id]/memory. Workspace delete → full cascade. GDPR SAR on request, < 30 days.
Sub-processors
LiveVercel (hosting), Supabase (database + auth), Anthropic (LLM), ElevenLabs (voice TTS), Stripe (payments), WorkOS (SSO), Resend (transactional email). Full list with DPAs on request.
EU data residency
In progressTenant-level flag that pins database + edge functions to eu-west-2. Available on the Enterprise tier. Default for all EU-incorporated customers by Q3.
SOC 2 Type I
In progressTargeted Q3 2026. Vanta controls in place; penetration test scheduled; policy documentation + attestation by external auditor underway. Type II report follows 12 months after.
ISO 27001 + 27701
PlannedGap analysis scheduled post-SOC 2 Type II. Expected 2027.
Penetration testing
In progressAnnual external penetration test (scoped to API + web surface). Remediation SLAs enforced. Summary redacted report available under NDA for prospects with > €50k ACV.
Enterprise security review pack
For deals > €50k ACV: we ship a pre-populated SIG-lite + architecture diagram + sub-processor list on request. Turn-around < 48 hours.
trust@caugia.com →Report a security issue: security@caugia.com. We triage within 1 business day. Responsible disclosure is welcomed; hall-of-fame page in preparation.