Security

Security you can trust

Your data is sensitive. We treat it that way. See our features for privacy controls.

Last updated: March 26, 2026

How we think about security

Four principles guide every decision we make about your data.

Security by design

Built in from day one, not bolted on after.

Least privilege

Access only what's needed, nothing more.

Defense in depth

Multiple layers, not single points of failure.

Transparency

We tell you what we do and how.

Your data, protected

Multiple layers of protection keep your information safe at every stage.

Encryption in transit

All data encrypted via TLS 1.3.

Encryption at rest

Infrastructure-level encryption (AWS). Field-level encryption via Supabase Vault for sensitive data.

Private fields

Sensitive data stored separately, never exposed to AI.

Encrypted fields

Highest sensitivity data lives in Supabase Vault.

Multi-tenant isolation

Your data is yours. Complete workspace separation.

Compliance-ready

Whether you need GDPR, HIPAA, or SOC 2 compliance, ioZen has you covered.

● In Progress

GDPR

Privacy by design, data subject rights, DPA available, jurisdiction-specific disclosures. Working toward full compliance.

◐ Architecture Ready

HIPAA

Private and encrypted fields available for handling sensitive health data. BAA and full certification planned.

✓ Infrastructure Certified

SOC 2

Built on SOC 2 Type II certified infrastructure (Supabase, Vercel, Cloudflare). Platform-level audit planned.

● In Progress

CCPA

Do Not Sell policy, data access and deletion supported. Working toward full compliance.

Need a BAA or specific compliance documentation? Contact [email protected]

Built on trusted infrastructure

Every layer of our stack is backed by providers with proven security track records.

Layer Provider Certification
Database Supabase (PostgreSQL) SOC 2 Type II
Authentication Supabase Auth SOC 2 Type II
Storage Supabase Storage SOC 2 Type II
Application & AI Vercel (Hosting, AI Gateway, Blob Storage) SOC 2 Type II
CDN Cloudflare SOC 2 Type II, ISO 27001

Platform and API hardening

March 2026 and later releases ship the controls below.

Atomic credit billing resets

Credits reset per billing period in one atomic operation. Concurrent requests cannot double-reset usage.

Rate limits on public credit status

The public credit status endpoint is rate limited to reduce automated scraping and enumeration.

Sanitized credit responses for anonymous callers

Unauthenticated requests do not receive exact credit counts or full plan details.

CUID validation on IDs

IDs are validated with Zod and CUID rules. Malformed input is rejected before it reaches the database.

Cross-bot update guards

A submission stays bound to the IntakeBot that received it. Another bot cannot update it.

Sanitized validation errors

Validation error responses do not expose internal schema structure.

Geolocation permission policy

Permissions-Policy and iframe allow attributes define how geolocation works in embedded, cross-origin contexts.

You control the sensitivity

For every field in your FlowApp, you decide how it's stored and whether AI can access it.

Standard

AI access

Full

Storage

Normal database

Best for

Most fields

Private

AI access

Never

Storage

Separate table

Best for

PII, sensitive info

Private + Encrypted

AI access

Never

Storage

Encrypted vault

Best for

SSN, medical, financial

Frequently asked questions

Is ioZen HIPAA compliant?

Our architecture supports HIPAA requirements through private and encrypted fields. Contact us to discuss your specific compliance needs and BAA arrangements.

Where is data stored?

Data is stored in Supabase's infrastructure (AWS, US regions by default). Contact us if you have specific region requirements.

Does AI see all my data?

No. Private fields are never sent to AI models. AI requests are routed through Vercel AI Gateway to providers like OpenAI, Anthropic, Google, and xAI, but only for fields you choose. You control which fields use AI and which stay completely isolated.

Can I delete all my data?

Yes. Full data deletion is available at any time. Contact support for workspace-level deletion.

Do you sell data?

No. Never. Your data is yours. Period.

Questions about security?

Our team is here to help with security reviews, compliance documentation, and BAA requests.

Ready to get started?

Enterprise-grade security. Consumer-grade experience. Start free today.

Free forever plan Live in 5 minutes No credit card