Trust

Security at Stateful

Application controls

Data protection

Browser traffic is served through Vercel over HTTPS. Server connections to Supabase and Plaid use HTTPS/TLS. Supabase provides database/storage encryption at rest. Plaid access tokens receive an additional application layer of AES-256-GCM encryption before storage. Secrets are server-only and are not intentionally included in browser bundles or telemetry.

Secure development

Changes are version controlled in GitHub and checked with TypeScript, ESLint, automated accounting/security tests, production builds, dependency audits, Dependabot, and provider security advisors. Remediation targets are 24–48 hours for critical issues, 7 days for high, 30 days for medium, and 90 days for low issues.

Providers and boundaries

Stateful relies on Vercel, Supabase, Plaid, Stripe, GitHub, and configured email delivery. Stripe-hosted Checkout and the customer portal process payment details; Stateful stores only billing identifiers and subscription state. Cloudflare Turnstile may protect authentication when configured. OpenAI is optional.

Current posture

Stateful has not claimed SOC 2, ISO 27001, PCI DSS, or another independent security certification. Founder Early Access does not yet have enterprise centralized IAM, automated workforce deprovisioning, endpoint vulnerability scanning, a public bug bounty, or a completed disaster-recovery restore exercise.

Report a concern

Private-beta users should report suspected vulnerabilities, account compromise, or data exposure immediately through the contact channel in their invitation. Do not include credentials, Plaid tokens, banking passwords, or live financial data in an initial report.