Customer feedback is sensitive. We treat it that way.
Encryption, access controls, regional data residency, and an audit log that survives an audit. Below is what's shipped today and what's on the near-term roadmap.
Encryption everywhere.
TLS in transit. AES-256 at rest by default on Google Cloud. Sensitive integration credentials are additionally encrypted with AES-256-GCM. Per-tenant data isolation.
Identity + access.
Sign in with email or Google via Firebase Authentication. Role-based access; staff access to production data is limited and logged. SAML / SSO and SCIM provisioning are on our roadmap.
Data residency.
Customer data is hosted in the United States (Google Cloud, us-central1), including backups.
Production reliability.
Multi-zone deploys. Daily backups with point-in-time restore. 99.9% SLA on paid plans. Status page with incident history.
Audit + observability.
Access and administrative actions are logged through Google Cloud audit logging, and we monitor for anomalous activity.
Privacy by design.
GDPR- and CCPA-aligned. Data-subject and deletion requests honored. Data minimization on collection. Per-customer retention policies.
Where we stand, honestly.
We're pre-launch, so we won't claim certifications we don't hold. Here's exactly where we are today and where we're going.
- SOC 2 Type IIIn progress · Q3 2026
- ISO 27001Roadmap · 2026
- GDPR · CCPACompliant today
- PCI DSSOut of scope (Stripe handles card data)
Found a vulnerability? We owe you a thank-you.
Email security@informly.co — PGP key available on request. We acknowledge within 24h, triage within 72h, and publicly credit researchers (with permission) once a fix ships.