Security is the service.
We hold information that belongs to other people. Protecting it is not a feature of what we do. It is the whole point.
This page tells you plainly where we stand: what is in place today, what we are building for our client portal, and what is on our roadmap. We would rather show you exactly where we are than overstate it.
Last updated July 10, 2026
In place today
What protects your information now.
Live today.
- This website is served only over encrypted connections (HTTPS), with strict transport security and a valid certificate.
- We use no third-party tracking or advertising anywhere on this site.
- Our infrastructure runs on providers that hold SOC 2 certification: Vercel for hosting, and Supabase for the coming portal database. We build on the security of their certified infrastructure.
- Our own accounts require multi-factor authentication, and every person has a unique login with no shared accounts. We use password managers, full-disk encryption on our devices, and US-based data hosting.
- Our business model is itself a safeguard. We never take custody of client funds, the client's own officer signs every state filing, and nothing is filed or mailed without a person approving it.
- Our website assistant works at the business level and never needs personal records. As a backstop, text formatted like a Social Security number is masked before a chat is processed or stored. This is a best-effort safeguard, not a substitute for keeping such details out of the chat.
As we build the client portal
The controls we are putting in place.
Being implemented before any real client data enters the system.
- Each client's data is isolated so that one client can never see another's.
- Social Security numbers are encrypted, shown only as the last four digits in the interface, and never placed in logs, exports, or prompts sent to an AI model.
- Every access to data is recorded in an audit log.
- Raw files that clients upload are automatically deleted after we process them, on a set schedule.
- Portal users must use multi-factor authentication, sessions time out, and staff access is limited to the minimum each role needs.
- Before any data is sent to an AI model, sensitive fields are masked first.
On our roadmap
Where we are headed.
Planned, and honest about it.
- We are pursuing SOC 2 certification (Type I, then Type II), the standard that mid-size and government buyers look for.
- Every client will be offered a Data Processing Agreement before onboarding.
- We are writing a formal incident response plan and will meet breach-notification commitments. All fifty states have breach-notification laws.
- We will pursue further government authorizations, such as GovRAMP, if and when a contract requires them.
Who touches your data
Our subprocessors.
These are the outside providers that may process data on our behalf. We keep this list current as our service evolves, so this is where any new provider would appear.
- Supabase In use
- Database and authentication. United States.
- Vercel In use
- Website hosting and content delivery. United States.
- Anthropic In use
- AI that powers our website assistant. Text formatted like a Social Security number is masked before it is sent, and for the coming portal only masked data will be processed. United States.
- Microsoft In use
- Microsoft 365 email for internal briefs, and Microsoft Bookings to schedule Health Check calls using the name, email, and phone number you provide. United States.
- Lob Planned
- Printing and mailing of owner letters. United States.
Our commitments
What we will never do.
- Never take custody of your funds.
- Never sell your data.
- Never send unmasked Social Security numbers to an AI model.
- Never file or mail anything without a person approving it.
- Never bring federal tax information into scope.
Report a concern
Found something?
If you believe you have found a security issue, email security@reclaimlogix.com and we will respond promptly.