Security at Stateful
Stateful uses layered application and provider controls and documents what is operational today—without claiming certifications or controls that are not in place.
Effective August 12, 2026 · Last updated August 12, 2026
Application controls
- Supabase Auth sessions with TOTP multi-factor authentication for privileged roles.
- Organization-scoped row-level security and role-based permissions.
- Owner/admin approval boundaries for posting and other high-risk accounting actions.
- Balanced, deterministic server-side posting with period locks and append-only audit events.
- Plaid transactions enter staging and never post directly to the general ledger.
- Personal account balances remain outside entity balance sheets.
Data protection
Browser traffic is served through Vercel over HTTPS. Server connections to Supabase and Plaid use HTTPS/TLS. Supabase provides database/storage encryption at rest. Plaid access tokens receive an additional application layer of AES-256-GCM encryption before storage. Secrets are server-only and are not intentionally included in browser bundles or telemetry.
Secure development
Changes are version controlled in GitHub and checked with TypeScript, ESLint, automated accounting/security tests, production builds, dependency audits, Dependabot, and provider security advisors. Remediation targets are 24–48 hours for critical issues, 7 days for high, 30 days for medium, and 90 days for low issues.
Providers and boundaries
Stateful relies on Vercel, Supabase, Plaid, GitHub, and configured email delivery. Cloudflare Turnstile may protect authentication when configured; Cloudflare DNS, WAF, and rate limiting are not currently in Stateful’s request path. OpenAI is optional. Stripe billing is not active.
Current posture
Stateful has not claimed SOC 2, ISO 27001, PCI DSS, or another independent security certification. The private beta does not yet have enterprise centralized IAM, automated workforce deprovisioning, endpoint vulnerability scanning, a public bug bounty, or a completed disaster-recovery restore exercise.
Report a concern
Private-beta users should report suspected vulnerabilities, account compromise, or data exposure immediately through the contact channel in their invitation. Do not include credentials, Plaid tokens, banking passwords, or live financial data in an initial report.