Security

Built like it handles your books and your inbox. Because it does.

ChurnRisk reads the two most sensitive systems a business runs. This page describes the controls in plain language, including what we have not completed yet. Nothing here claims more than we can show.

The controls

Isolation

Every tenant's data is isolated with row-level security enforced in the database itself, not only in application code. Cross-tenant access is treated as impossible by design and tested as a permanent regression on every release. Third-party credentials are encrypted per tenant with envelope encryption.

Access and least privilege

Connections are read-only wherever the provider allows it, and scoped to the minimum needed. Six roles govern who can see and approve what, and every view, approval, send, and export is recorded in an append-only audit log.

Data minimization

We store structured signals, short verbatim excerpts, and links back to source records, rather than copies of your mailbox. No model is trained on your data. Retention is configurable, export is always available, and deletion removes derived data as well as raw records.

Third parties

Subprocessors

Every provider that touches customer data, what it does, where it runs, and whose assessment stands behind it. Changes to this list are announced to customers before they take effect.

ChurnRisk subprocessors, their purpose, processing region, and published assurance status
ProviderPurposeRegionAssurance published by the provider
UnipileEmail and calendar access brokerageFrance, European UnionSOC 2 Type II, CASA Tier II, GDPR
NeonManaged Postgres databaseNot named by the providerSOC 2, SOC 3, ISO/IEC 27001, ISO/IEC 27701, HIPAA, GDPR
VercelApplication hostingNot named by the providerSOC 2, ISO/IEC 27001, PCI DSS, HIPAA, HITECH, GDPR
TwilioVoice and SMS, isolated subaccount per tenantNot named by the providerSOC 2, ISO/IEC 27001, ISO/IEC 27017:2015, ISO/IEC 27018:2019, PCI DSS v4.0.0
AnthropicSignal extraction and drafting, with no training on tenant contentNot named by the providerNot verified for publication

Each entry in the last column reproduces what that provider stated on its own trust page when we read it on 7 August 2026, and nothing else. Where a provider lists a standard without a type or a revision year, this table lists it the same way. Anthropic's trust page did not return readable content when we checked, so no assurance is claimed for it here. These are the providers' own statements, not ours, and we recheck them before publication. Anthropic's published commercial terms state that it may not train models on customer content from its services.

Our own position

Where we are on SOC 2

ChurnRisk is built to SOC 2 control expectations and we maintain readiness documentation, but we do not yet hold a SOC 2 report of our own, and we will not imply otherwise. Our email access provider holds SOC 2 Type II and CASA Tier 2. When our own audit is complete, this page will say so plainly. Until then, we will answer any security questionnaire directly.

Incidents

We maintain a written incident response process with commitments to notify affected customers promptly and in plain language. Ask us for it.

Contact

Ask us the hard questions.

Security reviews, questionnaires, and pointed questions from your IT contact are welcome and answered by the people who built the system.