Trust Center

Security & compliance

Everything a security review needs, in one place. If you have been asked to collect our compliance documentation, this page is the link to send — every document below is public, current, and needs no NDA to read.

Documents

How we protect customer data

Tenant isolation

Every record is scoped to a workspace and enforced in the database by Postgres row-level security, not only in application code. A query that omits the workspace returns nothing rather than another agency's rows.

Encryption

Data is encrypted in transit with TLS 1.2+ and at rest by the hosting provider. Card details are tokenized in the browser by a PCI DSS Level 1 provider and never reach JourneyFuse servers.

Authentication

Passwords are hashed and never stored in plaintext. Magic-link and OAuth sign-in are supported, sessions are short-lived, and access to a workspace is granted per member with a role.

Hosting

The application runs on Vercel with the database on Supabase (AWS, United States). Backups are taken continuously with point-in-time recovery.

Monitoring

Application errors are captured with personal data scrubbed before transmission. Uptime, delivery and cron health are checked continuously and reported on the status page.

Data portability and deletion

Customers can export their data at any time and can request deletion of a workspace, which removes customer data from production systems and, on the backup cycle, from backups.

Certifications

JourneyFuse is not currently SOC 2 or ISO 27001 certified, and we would rather say so plainly than leave it to be discovered mid-review. Card data is handled exclusively by a PCI DSS Level 1 certified provider, and our infrastructure providers — listed on the sub-processors page — maintain their own SOC 2 Type II attestations.

Reporting a vulnerability

Email security@journeyfuse.com with the details. We acknowledge reports within two business days and will keep you updated until the issue is resolved. Please give us a reasonable window to remediate before disclosing publicly.

Have a security questionnaire, or need the DPA countersigned? Email security@journeyfuse.com and we will turn it around.