Trust

Security at Stateful

Application controls

Data protection

Browser traffic is served through Vercel over HTTPS. Server connections to Supabase and Plaid use HTTPS/TLS. Supabase provides database/storage encryption at rest. Plaid access tokens receive an additional application layer of AES-256-GCM encryption before storage. Secrets are server-only and are not intentionally included in browser bundles or telemetry.

Secure development

Changes are version controlled in GitHub and checked with TypeScript, ESLint, automated accounting/security tests, production builds, dependency audits, Dependabot, and provider security advisors. Remediation targets are 24–48 hours for critical issues, 7 days for high, 30 days for medium, and 90 days for low issues.

Providers and boundaries

Stateful relies on Vercel, Supabase, Plaid, GitHub, and configured email delivery. Cloudflare Turnstile may protect authentication when configured; Cloudflare DNS, WAF, and rate limiting are not currently in Stateful’s request path. OpenAI is optional. Stripe billing is not active.

Current posture

Stateful has not claimed SOC 2, ISO 27001, PCI DSS, or another independent security certification. The private beta does not yet have enterprise centralized IAM, automated workforce deprovisioning, endpoint vulnerability scanning, a public bug bounty, or a completed disaster-recovery restore exercise.

Report a concern

Private-beta users should report suspected vulnerabilities, account compromise, or data exposure immediately through the contact channel in their invitation. Do not include credentials, Plaid tokens, banking passwords, or live financial data in an initial report.