Security

We take your data and your customers' data seriously. Here's how we handle security.

Today

  • • Vercel infrastructure with SOC 2 Type II compliance
  • • Neon Postgres with encryption at rest and in transit
  • • Integration credentials encrypted at rest (AES-256-GCM)
  • • Clerk for authentication, with optional SSO
  • • Webhook signature verification on all inbound webhooks
  • • Rate-limiting on all public endpoints
  • • Vercel BotID on signup and payment endpoints
  • • Quarterly secret rotation

Roadmap

  • • SOC 2 Type II certification — observation period begins Month 6
  • • Annual third-party penetration test — starting Month 9
  • • HackerOne-style bug bounty — Month 6

Reporting a vulnerability

See our security.txt or email security@growlift.com.