Your data runs our customers' businesses, so security isn't a feature we bolted on, it's how the platform is built. Encryption everywhere, database-level tenant isolation, strict access controls, and human-in-the-loop AI governance are all operating in production today.
Our SOC 2 Type I audit is actively underway with an engaged third-party auditor. We publish our full controls, subprocessor list, and audit timeline below, because serious buyers deserve specifics, not vague badges.
Trust center last reviewed June 2026 · Privacy policy effective April 24, 2026
Everything below ladders up to these. They are not aspirations, they are how the platform is built.
Row-Level Security on every tenant table means one customer can never see another's data, enforced by the database, not just application code.
Your prompts and records are never used to train models. We use zero-data-retention provider tiers wherever they're offered, and we put it in writing in every contract.
Full export on demand, right-to-erasure within 30 days, scoped API keys you can rotate or revoke instantly, and an immutable audit trail of every action.
These practices are operating now. They form the foundation for our SOC 2 audit work and any enterprise vendor review.
We publish our roadmap because honesty about timing is more useful to vendor reviewers than a vague claim. Here is exactly where we are.
Encryption, RLS, audit logging, RBAC, and AI governance are operating in production and mapped to the SOC 2 Common Criteria. Our formal Type I audit with a third-party auditor is in progress.
Wire automated evidence collection (audit log, RBAC, encryption signals, vendor inventory). Complete vendor security questionnaires for prospective customers.
Engage a third-party auditor (e.g., Prescient Assurance, Schellman, or Barr Advisory) for the Type I attestation.
Complete the 12-month observation window and Type II attestation. Make report available to enterprise customers under NDA.
Third-party penetration test annually. GDPR / CCPA-compliant DPA available for any customer on request.
We notify customers at least 30 days in advance of adding a new subprocessor that processes customer data. Email info@expertailabs.com to receive change notifications.
| Subprocessor | Purpose | Location | Compliance |
|---|---|---|---|
Vercel, Inc. | Application hosting, serverless compute, edge network, build pipeline | United States | SOC 2 Type IIISO 27001GDPR |
Supabase, Inc. | Primary database, authentication, file storage, row-level security | United States (us-east-1) | SOC 2 Type IIHIPAA-eligible plan available |
Anthropic, PBC | Large language model inference for content generation, classification, summarization We use Anthropic's zero-retention configuration. Tenant data is not used to train models. | United States | SOC 2 Type IIZero data retention API tier |
OpenAI, L.L.C. | Large language model inference, audio transcription (Whisper), embeddings, vision We use OpenAI's API zero-retention configuration where supported. Tenant data is not used to train models. | United States | SOC 2 Type IIZero data retention API tier |
Resend, Inc. | Transactional email delivery, deliverability monitoring, webhook event stream | United States | SOC 2 Type II |
Twilio, Inc. | SMS, voice, programmable messaging for lead-intake callback flows | United States | SOC 2 Type IIISO 27001HIPAA-eligible |
CallRail, LLC | Inbound call tracking, recording, transcription source | United States | SOC 2 Type IIPCI DSS |
Google LLC (Workspace, Ads, Maps Platform) | Email infrastructure (Workspace), conversion event reporting (Ads), business listing data (Maps), reCAPTCHA | United States | SOC 2 Type IIISO 27001ISO 27017ISO 27018 |
SemRush Inc. | SEO research, keyword ranking, competitive analysis | United States | SOC 2 Type II |
HeyGen Labs, Inc. | AI video generation from text scripts (per-franchise avatar configured manually) | United States | SOC 2 Type II |
Cloudflare, Inc. | DNS, CDN, DDoS protection, bot management for public marketing surface | Global edge | SOC 2 Type IIISO 27001PCI DSS |
We commit to 24-hour breach notification from the moment a security incident affecting customer data is confirmed.
Our incident response runbook covers: detection, containment, customer notification, regulator notification (where required), root-cause analysis, and post-incident review with corrective actions.
Customers receive a written incident report within 14 days of containment, with redactions only where legally required.
Report a security incidentWe welcome reports from security researchers and offer safe-harbor for good-faith research.
We respond to security questionnaires within 5 business days. DPA available on request. Penetration test results and SOC 2 evidence shared under NDA once reports are issued.