Security & trust

Built for the people who ask hard questions.

Your contracts are sensitive and your buyers are discerning. SaaSoT is built security-first, with isolation, access control, and a complete audit trail by default.

Row-level multi-tenant isolationMFA + role-based access controlFull audit logReversible adjustmentsAggregates-only AIZero-data-retention AI postureEncryption in transitSOC 2 readiness underway

Tenant isolation

Multi-tenant architecture with row-level security in the database — each customer's data is separated and access-scoped at the data layer, not just the app.

Access control

Multi-factor authentication (TOTP) and role-based access control, so people see only what their role allows. Anonymized views for board and investor users.

Auditability

A complete audit log of changes, and manual adjustments that are explicitly noted and reversible — every number can be traced to how it was produced.

AI privacy

AI commentary is generated from aggregates only — no individual customer names or PII are sent to the model — under a zero-data-retention posture.

Infrastructure

Hosted on managed, reputable infrastructure (Supabase Postgres and Railway) with encryption in transit and managed backups.

Compliance roadmap

SOC 2 readiness is underway and third-party penetration testing is planned. We're happy to walk security teams through current controls.

Security and compliance posture evolves as we grow; this page reflects where things stand today. Reach out for current details or a security review.

Early access

Become a source-of-truth early partner.

Tell us where you're coming from and we'll be in touch. No spam, ever.