Security & Data Privacy

You're uploading insurance certificates and tax documents. Here's exactly how we protect them.

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Files stored in our system are never placed in a public bucket — all document storage is private by default, with access gated through signed URLs generated per request.

US-Based Infrastructure

All customer data is hosted in the United States. SubVerify runs on Supabase (PostgreSQL) for the database layer and Vercel's edge network for application delivery. No data is processed or stored outside the US.

Access Controls

SubVerify enforces strict role-based access. General contractors can only view their own subcontractors and associated documents. Subcontractors can only see documents they uploaded. Cross-tenant data access is architecturally impossible by design — not just a policy.

Document Security

All uploaded documents — Certificates of Insurance, W-9s, contractor licenses, and other compliance files — are stored in a private, non-public storage bucket. To access a file, a short-lived signed URL is generated per request. Documents cannot be accessed via a guessable or permanent public URL.

Audit Trail

Every document upload, approval, rejection, and access event is logged with a timestamp and the user ID of the actor. If you ever need to prove compliance during a dispute or audit, the complete paper trail is there and exportable.

Data Retention & Deletion

You can export or delete your data at any time from your account settings. Subcontractor data is retained for the duration of your active subscription. Upon account cancellation, data deletion requests are honored within 30 days.

Incident Response

In the event of a confirmed security incident affecting customer data, affected customers will be notified within 72 hours of our awareness. Notifications include the nature of the incident, the data involved, and steps we are taking to remediate.

Compliance

SubVerify is built with SOC 2 principles in mind, including security, availability, and confidentiality controls. Our data handling practices are GDPR-aware, including support for data export and deletion requests.

Questions about security?

We're happy to answer specific questions about our security practices, data handling, or compliance posture.

Email us at contact@warrenandsabb.com