Security and trust
Controls stated at the level we can support.
Embargo applies application and operational safeguards and relies on managed service providers for parts of the stack. Provider certifications belong to those providers; they do not certify Embargo itself.
Security contact
Report a potential vulnerability privately. Do not include live credentials or unnecessary personal data.
security@getembargo.comApplication controls
Four control families around the service.
This is a concise posture summary, not a certification report or a guarantee that every security event can be prevented.
- 01
Identity and tenant boundaries
Clerk manages authentication and sessions. Customer records are scoped to the authenticated organization, while administrative routes and service-role registry access remain server-side.
- 02
Public exposure controls
Public screening is rate-limited and returns a bounded evidence view. The underlying entity registry is not exposed through a permissive anonymous database policy.
- 03
Evidence integrity
Screening evidence is versioned and checked for completeness before eligible exports or certificates are issued. Invalidated evidence cannot silently retain a current certificate state.
- 04
Change and operational checks
Automated checks cover authentication boundaries, public API rate limiting, secret patterns, database-policy changes, build integrity, dependency updates, production routes, and feed health.
Service providers
Know which provider does what.
The list below is shared with the Privacy Policy to reduce drift. Each external link leads to the provider's own security, compliance, or data-protection material; review those sources for their current claims.
Clerk
User authentication, session management, and Google OAuth sign-in
Recorded location · United States
OAuth identity provider for Google Sign-In via Clerk, and Google Gemini for source-grounded enrichment, classification, drafting, and evaluation tasks.
Recorded location · United States
Google Sign-In provides name and email only. Public regulatory or entity evidence and screening counts may be sent separately to configured Google AI services. Private investigation notes and the submitted search field are excluded from review-drafting input.
Supabase
Database hosting, storage, and row-level-secure data access
Recorded location · United States
Stripe
Payment processing and subscription management
Recorded location · United States
Resend
Transactional and digest email delivery
Recorded location · United States
GLEIF
Legal Entity Identifier (LEI) data for ownership chain resolution
Recorded location · Switzerland
We query publicly available corporate registry data only. No personal data is sent to GLEIF.
Vercel
Application hosting, CDN, and edge functions
Recorded location · United States
Data handling
Start with the data map.
The Privacy Policy records the data categories Embargo collects, why they are used, subprocessors, retention, customer rights, and the role of configured AI services. Payment-card details are processed by Stripe and are not stored on Embargo servers.
Read the Privacy PolicyCurrent procurement boundary
Ask before assuming a control or document exists.
- Embargo is not represented as independently certified under SOC 2 or ISO 27001.
- A standard customer Data Processing Agreement is still being prepared and is not agreed until approved in writing.
- SSO and SCIM are not standard self-service capabilities today.
- Business includes API access; implementation and security requirements should be confirmed before purchase.
Responsible disclosure
Send a concise description, affected route, reproduction steps, and impact. We will acknowledge the report and investigate based on severity and available evidence.