09COMPANY
Security
Last updated · 20 August 2026
You are sending us order-level financial data. This page states, plainly, how it is handled.
1. Encryption
- In transit: TLS 1.2 or higher on every connection, HSTS enabled.
- At rest: AES-256 storage encryption for uploaded files, reports and backups.
2. Access control
- Least-privilege, role-based access; production access limited to named personnel.
- Multi-factor authentication required for all internal and infrastructure accounts.
- Access to uploaded files is logged and reviewed; access is revoked on role change or exit.
- Customer data is logically segregated per account; environments are separated.
3. File retention and deletion
Uploaded order and remittance files are deleted 30 days after your report is delivered, and immediately on request to privacy@codaudit.com. Reports are retained for the life of the account and deleted within 30 days of closure. Backups age out within 30 days.
4. Infrastructure and sub-processors
- Vercel Inc. — application hosting and file storage — European Union (Frankfurt)
- Stripe — payment processing and billing. We do not store card numbers.
- Resend — transactional email
- Cloudflare, Inc. — DNS, email routing and cookieless web analytics (aggregate data retained 6 months)
- Lovable AI Gateway — AI inference for the support assistant, currently routed to Google Gemini models. Chat text only, never uploaded files.
Security contact: security@codaudit.com.
5. Development practice
- Peer-reviewed changes, versioned deployments, and the ability to roll back.
- Dependency and vulnerability scanning on the application and its packages.
- Secrets held in a managed secret store, never in source control.
6. Incident response
Suspected incidents are triaged immediately, contained, and investigated. Affected customers are notified without undue delay and within 72 hours of confirmation, with scope, impact and remediation. Regulators are notified where the law requires it. A post-incident review is shared with affected customers on request.
7. Responsible disclosure
Report a vulnerability to security@codaudit.com. Please include reproduction steps and give us reasonable time to remediate before publishing. We will acknowledge within 3 business days and will not pursue action against good-faith research that avoids privacy violations, data destruction and service disruption.
8. Compliance posture
We hold no third-party security certifications at this time, and claim none. Security documentation is available under NDA: security@codaudit.com.