Security and trust

Controls stated at the level we can support.

Embargo applies application and operational safeguards and relies on managed service providers for parts of the stack. Provider certifications belong to those providers; they do not certify Embargo itself.

Security contact

Report a potential vulnerability privately. Do not include live credentials or unnecessary personal data.

security@getembargo.com

Application controls

Four control families around the service.

This is a concise posture summary, not a certification report or a guarantee that every security event can be prevented.

  1. 01

    Identity and tenant boundaries

    Clerk manages authentication and sessions. Customer records are scoped to the authenticated organization, while administrative routes and service-role registry access remain server-side.

  2. 02

    Public exposure controls

    Public screening is rate-limited and returns a bounded evidence view. The underlying entity registry is not exposed through a permissive anonymous database policy.

  3. 03

    Evidence integrity

    Screening evidence is versioned and checked for completeness before eligible exports or certificates are issued. Invalidated evidence cannot silently retain a current certificate state.

  4. 04

    Change and operational checks

    Automated checks cover authentication boundaries, public API rate limiting, secret patterns, database-policy changes, build integrity, dependency updates, production routes, and feed health.

Data handling

Start with the data map.

The Privacy Policy records the data categories Embargo collects, why they are used, subprocessors, retention, customer rights, and the role of configured AI services. Payment-card details are processed by Stripe and are not stored on Embargo servers.

Read the Privacy Policy

Current procurement boundary

Ask before assuming a control or document exists.

  • Embargo is not represented as independently certified under SOC 2 or ISO 27001.
  • A standard customer Data Processing Agreement is still being prepared and is not agreed until approved in writing.
  • SSO and SCIM are not standard self-service capabilities today.
  • Business includes API access; implementation and security requirements should be confirmed before purchase.
Evaluate procurement fit

Responsible disclosure

Send a concise description, affected route, reproduction steps, and impact. We will acknowledge the report and investigate based on severity and available evidence.

Report privately