Security
The controls behind every connection.
ChurnRisk reads your books and selected inboxes. This page names the controls around that access and the audit work we have not completed yet.
The controls
Isolation
Every tenant's data is isolated with row-level security in the database. Application checks add another layer. Permanent regression tests try to cross tenant boundaries on every release, and third-party credentials are encrypted separately for each tenant.
Access and least privilege
Connections are read-only wherever the provider allows it, and scoped to the minimum needed. Six roles govern who can see and approve what. Approvals, connection changes, exports, and other sensitive mutations write to an append-only audit log. Selected API and evidence reads are audited; ordinary page views are not recorded today.
Data minimization
We store structured signals, short verbatim excerpts, and links back to source records, rather than copies of your mailbox. No model is trained on your data. Retention is configurable, export is always available, and deletion removes derived data as well as raw records.
Third parties
Subprocessors
See which provider handles each job, the region it publishes, and the assurance it claims. We announce changes to customers before they take effect.
| Provider | Purpose | Region | Assurance published by the provider |
|---|---|---|---|
| Unipile | Email and calendar access brokerage | France, European Union | SOC 2 Type II, CASA Tier II, GDPR |
| Neon | Managed Postgres database | Not named by the provider | SOC 2, SOC 3, ISO/IEC 27001, ISO/IEC 27701, HIPAA, GDPR |
| Firebase Authentication (Google) | Account creation, email verification, and sign-in | Not named by the provider | Not verified for publication |
| Stripe | Subscriptions, payment methods, invoices, and receipts | Not named by the provider | Not verified for publication |
| Vercel | Application hosting | Not named by the provider | SOC 2, ISO/IEC 27001, PCI DSS, HIPAA, HITECH, GDPR |
| Twilio | Voice and SMS, isolated subaccount per tenant | Not named by the provider | SOC 2, ISO/IEC 27001, ISO/IEC 27017:2015, ISO/IEC 27018:2019, PCI DSS v4.0.0 |
| Anthropic | Signal extraction and drafting, with no training on tenant content | Not named by the provider | Not verified for publication |
The last column records what each provider published on its own trust page when we checked on August 7, 2026. We do not add a type or revision year when the provider leaves it out. Anthropic's trust page did not return readable content, so its row carries no assurance. These statements belong to the providers. We check them again before updating this page. Anthropic's published commercial terms state that it may not train models on customer content from its services.
Verify the published statements on the providers' own pages: Unipile security, Neon Trust Center, Vercel Security, Twilio Security, and Anthropic commercial terms.
Our own position
Where we are on SOC 2
ChurnRisk is built to SOC 2 control expectations and maintains readiness documentation. We do not hold a SOC 2 report of our own. Our email access provider holds SOC 2 Type II and CASA Tier 2. We answer security questionnaires directly while our own audit remains incomplete.
Incidents
We maintain a written incident response process with commitments to notify affected customers promptly and in plain language. Ask us for it.
Contact
Ask us the hard questions.
Security reviews, questionnaires, and pointed questions from your IT contact are welcome and answered by the people who built the system.