Security

The controls behind every connection.

ChurnRisk reads your books and selected inboxes. This page names the controls around that access and the audit work we have not completed yet.

The controls

Isolation

Every tenant's data is isolated with row-level security in the database. Application checks add another layer. Permanent regression tests try to cross tenant boundaries on every release, and third-party credentials are encrypted separately for each tenant.

Access and least privilege

Connections are read-only wherever the provider allows it, and scoped to the minimum needed. Six roles govern who can see and approve what. Approvals, connection changes, exports, and other sensitive mutations write to an append-only audit log. Selected API and evidence reads are audited; ordinary page views are not recorded today.

Data minimization

We store structured signals, short verbatim excerpts, and links back to source records, rather than copies of your mailbox. No model is trained on your data. Retention is configurable, export is always available, and deletion removes derived data as well as raw records.

Third parties

Subprocessors

See which provider handles each job, the region it publishes, and the assurance it claims. We announce changes to customers before they take effect.

ChurnRisk subprocessors, their purpose, processing region, and published assurance status
ProviderPurposeRegionAssurance published by the provider
UnipileEmail and calendar access brokerageFrance, European UnionSOC 2 Type II, CASA Tier II, GDPR
NeonManaged Postgres databaseNot named by the providerSOC 2, SOC 3, ISO/IEC 27001, ISO/IEC 27701, HIPAA, GDPR
Firebase Authentication (Google)Account creation, email verification, and sign-inNot named by the providerNot verified for publication
StripeSubscriptions, payment methods, invoices, and receiptsNot named by the providerNot verified for publication
VercelApplication hostingNot named by the providerSOC 2, ISO/IEC 27001, PCI DSS, HIPAA, HITECH, GDPR
TwilioVoice and SMS, isolated subaccount per tenantNot named by the providerSOC 2, ISO/IEC 27001, ISO/IEC 27017:2015, ISO/IEC 27018:2019, PCI DSS v4.0.0
AnthropicSignal extraction and drafting, with no training on tenant contentNot named by the providerNot verified for publication

The last column records what each provider published on its own trust page when we checked on August 7, 2026. We do not add a type or revision year when the provider leaves it out. Anthropic's trust page did not return readable content, so its row carries no assurance. These statements belong to the providers. We check them again before updating this page. Anthropic's published commercial terms state that it may not train models on customer content from its services.

Verify the published statements on the providers' own pages: Unipile security, Neon Trust Center, Vercel Security, Twilio Security, and Anthropic commercial terms.

Our own position

Where we are on SOC 2

ChurnRisk is built to SOC 2 control expectations and maintains readiness documentation. We do not hold a SOC 2 report of our own. Our email access provider holds SOC 2 Type II and CASA Tier 2. We answer security questionnaires directly while our own audit remains incomplete.

Incidents

We maintain a written incident response process with commitments to notify affected customers promptly and in plain language. Ask us for it.

Contact

Ask us the hard questions.

Security reviews, questionnaires, and pointed questions from your IT contact are welcome and answered by the people who built the system.