Skip to main content
reconosint.
How it worksSample profileCompareStakeOutPricing
Sign inStart free

Security

Last updated: July 11, 2026

This page describes the security controls actually in place at reconosint today. We describe only what we do — not aspirations. Where we do not yet hold a formal certification, we say so plainly below.

Encryption

All traffic to and from the application is served exclusively over HTTPS (TLS), including the API and the profile-generation worker. Application data at rest — your account, generated profiles, and billing identifiers — is stored in managed Postgres on Supabase, which encrypts data at rest on the underlying storage volumes.

Authentication & access control

Authentication is handled by Supabase Auth (email and OAuth sign-in). Every application table is protected by Postgres Row-Level Security (RLS) so that a signed-in user can read and write only their own rows; the browser client uses a public, RLS-scoped key and never the service role. Privileged operations run server-side under a separate service role that is never exposed to the client.

Payments & PCI scope

All card data is handled by Stripe. Card numbers are entered directly into Stripe-hosted fields and never touch our servers or database, which keeps our PCI DSS scope minimized to SAQ-A. We store only billing identifiers such as your Stripe customer ID, billing email, and the last four digits of the payment method — never the full card number.

Data we store

Profiles describe company-level technology infrastructure assembled from third-party, publicly available sources. Profile bodies are entity-level only — they characterize an organization’s stack, not private personal data.

  • No sensitive personal data (government IDs, health, or financial account data) is stored in profiles.
  • Prospecting contacts reflect publicly listed business-role information, not private records.
  • Error monitoring (Sentry) captures stack traces and request metadata, not message bodies.

Our infrastructure sub-processors are listed, with their purpose and region, on the Sub-processors page.

Certifications

We do not currently claim SOC 2, ISO 27001, or HIPAA compliance, and we will not display any badge we cannot back with an artifact. We intend to pursue a formal SOC 2 audit as the business matures or on a qualified enterprise request; until that audit is complete, this page is the authoritative description of our controls.

Reporting a vulnerability

If you believe you have found a security issue, please email security@reconosint.ai. Our machine-readable policy is published at /.well-known/security.txt. We ask that you give us a reasonable window to remediate before any public disclosure.

Related

Privacy Policy · Terms of Service · Sub-processors · Accessibility Statement

reconosint.
PrivacyTermsSecuritySub-processorsAccessibilityStatusContact
© 2026 reconosint. · AI-powered sales intelligence