Security

Security and privacy, by design

Your data is sensitive. We treat it that way. ioZen runs on SOC 2 Type II certified infrastructure, with field-level encryption, multi-tenant isolation, and granular controls over what AI can and cannot see.

We're transparent about where we are on our compliance journey. Some certifications are inherited from our infrastructure providers; others are still in progress. This page tells you exactly which is which.

Last updated: April 27, 2026

How we think about security

Four principles guide every decision we make about your data.

Security by design

Built in from day one, not bolted on after.

Least privilege

Access only what's needed, nothing more.

Defense in depth

Multiple layers, not single points of failure.

Transparency

We tell you what we do and how.

Your data, protected

Multiple layers of protection keep your information safe at every stage.

Encryption in transit

All traffic uses TLS 1.3.

Encryption at rest (infrastructure)

Disk-level encryption provided by AWS via Supabase for all stored data.

Field-level encryption (Supabase Vault)

Fields explicitly marked Private + Encrypted are stored in Supabase Vault, separate from the main database.

Private fields

Fields marked Private are stored separately and are never sent to AI models or included in AI context.

Multi-tenant isolation

Workspaces are isolated using row-level security policies in Supabase, plus application-level workspace checks on every request.

Where we are on compliance

Here's where we actually stand: what's inherited from our providers, what's in progress, and what we don't support yet.

◐ Infrastructure inherited

SOC 2

ioZen runs on SOC 2 Type II certified providers (Supabase, Vercel, Cloudflare). ioZen itself is not yet SOC 2 certified; a platform-level audit is on our roadmap.

● In progress

GDPR

We follow GDPR principles (privacy by design, data subject rights, DPA available on request) and are working toward full compliance. We are not yet certified; we'll publish our DPIA and Records of Processing as that work progresses.

⚠ Not supported today

HIPAA

Our architecture (private and encrypted fields) is designed to support HIPAA workloads in the future, but we do not currently sign BAAs and ioZen should not be used to store or process PHI. Contact us and we'll let you know when it's ready.

● In progress

CCPA

We honor 'Do Not Sell' requests and support data access and deletion. Full CCPA program documentation is in progress.

Have compliance documentation requirements? Contact [email protected]

Built on trusted infrastructure

Every layer of our stack is backed by providers with proven security track records.

The certifications below belong to our sub-processors. They describe the infrastructure ioZen runs on, not an audit of ioZen itself. See the compliance section above for ioZen's own status. View the full sub-processor list.
Layer Provider Certification
Database Supabase (PostgreSQL) SOC 2 Type II
Authentication Supabase Auth SOC 2 Type II
Storage Supabase Storage SOC 2 Type II
Application & AI Vercel (Hosting, AI Gateway, Blob Storage) SOC 2 Type II
CDN Cloudflare SOC 2 Type II, ISO 27001

Platform and API hardening

March 2026 and later releases ship the controls below.

Atomic credit billing resets

Credits reset per billing period in one atomic operation. Concurrent requests cannot double-reset usage.

Rate limits on public credit status

The public credit status endpoint is rate limited to reduce automated scraping and enumeration.

Sanitized credit responses for anonymous callers

Unauthenticated requests do not receive exact credit counts or full plan details.

CUID validation on IDs

IDs are validated with Zod and CUID rules. Malformed input is rejected before it reaches the database.

Cross-bot update guards

A submission stays bound to the IntakeBot that received it. Another bot cannot update it.

Sanitized validation errors

Validation error responses do not expose internal schema structure.

Geolocation permission policy

Permissions-Policy and iframe allow attributes define how geolocation works in embedded, cross-origin contexts.

Operational security

How we run the platform day to day.

Access controls

All ioZen team members use SSO with mandatory MFA. Production access follows least-privilege and is logged.

Backups & recovery

Automatic daily database backups via Supabase. Recovery procedures are tested quarterly.

Vulnerability management

Dependencies are scanned automatically and our codebase is continuously reviewed by AI for vulnerabilities. Critical findings are addressed within days, not weeks.

Penetration testing

An independent penetration test is planned for May 2026.

Incident response

If a security incident affects customer data, we notify affected customers within 72 hours of confirmation, per GDPR Article 33.

You control the sensitivity

For every field in your FlowApp, you decide how it's stored and whether AI can access it.

Standard

AI access

Full

Storage

Normal database

Best for

Most fields

Private

AI access

Never

Storage

Separate table

Best for

PII, sensitive info

Private + Encrypted

AI access

Never

Storage

Encrypted vault

Best for

SSN, medical, financial

Report a vulnerability

Found a security issue? We welcome responsible disclosure.

Email [email protected] with details. We acknowledge within 2 business days.

Please give us reasonable time to remediate before public disclosure. We do not currently offer a paid bug bounty, but we publicly credit researchers (with permission).

A machine-readable disclosure policy is available at /.well-known/security.txt.

Frequently asked questions

Is ioZen SOC 2 certified?

Not yet. Our infrastructure providers (Supabase, Vercel, Cloudflare) are SOC 2 Type II certified; an ioZen platform-level audit is on our roadmap. We share our security questionnaire on request. Email [email protected].

Is ioZen HIPAA compliant?

Not today. Our architecture is designed to support HIPAA workloads, but we do not sign BAAs and ioZen should not be used to store or process PHI. Contact us to be notified when HIPAA support ships.

Where is data stored?

Data is stored in Supabase's infrastructure (AWS, US regions by default). Contact us if you have specific region requirements.

Does AI see all my data?

No. Private fields are never sent to AI models. AI requests are routed through Vercel AI Gateway to providers like OpenAI, Anthropic, Google, and xAI, but only for fields you choose. You control which fields use AI and which stay completely isolated.

Can I delete all my data?

Yes. Workspace deletion requests are completed within 30 days of receipt. Contact support to initiate.

Do you sell data?

No. Never. Your data is yours. Period.

Questions about security?

Security review, compliance docs, or questionnaire? We can help.

Transparent security. Real controls. Honest roadmap.

Start free today and see exactly what we protect, how we protect it, and what's still in progress.

Free forever plan Live in 5 minutes No credit card