Your data is yours. We take that seriously.
We don't have SOC 2 (yet). But we'll describe exactly what we do – so you can decide for yourself.
Encryption
TLS 1.3 in transit, AES-256 at rest. Passwords hashed via bcrypt through Supabase Auth.
Data isolation
Postgres Row-Level Security. Every query is bound to a user – nothing leaks by accident.
EU data residency
Supabase EU region (Frankfurt). Cloudflare R2 EU jurisdiction. No transfer outside the EEA.
Authentication
Magic link or email/password. JWTs with short expiry, rotating refresh tokens.
Backups
Daily automated backups with 30-day retention. Point-in-time recovery at the Supabase level.
Audit logs
Key actions (login, password change, client deletion) are logged with timestamp and IP.
What we don't promise
We'd rather describe where we stand than play buzzword bingo.
We don't have SOC 2 or ISO 27001. For a team our size that would mean more paperwork than real change – and the real change we already have.
If you need formal certification for corporate compliance, let us know. It's a valid request and we're actively watching the ecosystem.
Report a vulnerability: bezpecnost@pocketcoach.cz