CAUGIA · TRUST

How we handle your data.

Everything below is concrete. If a control says "Live" it's running in production now; if "In progress" there's a dated plan. No marketing-theatre.

Hosting + edge

Live

Vercel (EU-hosted functions available). Database + auth on Supabase (EU region for EU workspaces on request). No customer data leaves the EU when the EU-residency flag is set.

Encryption in transit + at rest

Live

TLS 1.3 everywhere. Supabase enforces at-rest encryption via pgcrypto. Client-side fields (OAuth tokens, API keys) encrypted with AES-256 before insert.

Authentication

Live

Password + magic link via Supabase Auth. Rate-limit + brute-force protection at the edge. SSO via WorkOS (Okta, Azure AD, Google Workspace) for enterprise tenants.

Row-level security

Live

Every tenant-scoped table enforces RLS. Workspace data is never joinable across tenants. Service-role key is server-only and never exposed client-side.

Audit trail export

Live

Every Sophie decision (confirmations, action transitions, gate flips) is logged immutably to decision_records. Exportable via /api/admin/audit-trail-export.

Rate limiting + abuse guards

Live

Per-IP + per-user rate limits on every Sophie turn + assessment submit. HMAC-signed webhooks with constant-time comparison. Certification quiz token enforces per-attempt choice shuffle.

Data retention + deletion

Live

Sophie memory entries are workspace-scoped and deletable from /workspace/[id]/memory. Workspace delete → full cascade. GDPR SAR on request, < 30 days.

Sub-processors

Live

Vercel (hosting), Supabase (database + auth), Anthropic (LLM), ElevenLabs (voice TTS), Stripe (payments), WorkOS (SSO), Resend (transactional email). Full list with DPAs on request.

EU data residency

In progress

Tenant-level flag that pins database + edge functions to eu-west-2. Available on the Enterprise tier. Default for all EU-incorporated customers by Q3.

SOC 2 Type I

In progress

Targeted Q3 2026. Vanta controls in place; penetration test scheduled; policy documentation + attestation by external auditor underway. Type II report follows 12 months after.

ISO 27001 + 27701

Planned

Gap analysis scheduled post-SOC 2 Type II. Expected 2027.

Penetration testing

In progress

Annual external penetration test (scoped to API + web surface). Remediation SLAs enforced. Summary redacted report available under NDA for prospects with > €50k ACV.

Enterprise security review pack

For deals > €50k ACV: we ship a pre-populated SIG-lite + architecture diagram + sub-processor list on request. Turn-around < 48 hours.

trust@caugia.com →

Report a security issue: security@caugia.com. We triage within 1 business day. Responsible disclosure is welcomed; hall-of-fame page in preparation.