Skip to main content

Security

Vendor security questionnaire

Pre-filled answers to the questions your security team will ask. Speeds up enterprise procurement.

Enterprise procurement always sends a vendor security questionnaire. Use the answers below as a starting point — we keep them current and accept supplementary questions in writing.

Organisation

QuestionAnswer
Legal entityCodivion, LLC
Registered jurisdictionUnited States (state on request)
Year founded2025
Employee count<10 (early-stage)
Primary contact for securitysecurity@codivion.com
Cyber liability insuranceIn progress (target Q2 2027)

Architecture + hosting

QuestionAnswer
Hosting providerVercel (compute), Supabase (data), Cloudflare (edge)
Primary regionus-east-1
Multi-region replicationDB read replicas: roadmap. Active-active: not yet.
Tenant isolationPostgres RLS on every tenant table
Network segmentationVercel-managed + Supabase VPC
Logical separation of customer dataEnforced at database level via Row Level Security policies

Authentication + access

QuestionAnswer
End-user authEmail/password, OAuth (Google, GitHub), SAML 2.0 SSO (Team+), OIDC (Team+)
Session storageHttpOnly Secure SameSite=Lax cookies
Session TTL30 days, refreshable
Internal admin authPlatform admin allowlist in DB (RLS-enforced)
MFA supportVia SSO IdP
Password policyNIST 800-63B aligned (length-first, no forced rotation)
Password storagePBKDF2-SHA256 with per-user salt + 100k iterations
API key storageSHA-256 hashed; never re-displayable after creation

Encryption

QuestionAnswer
In transitTLS 1.2+, HTTP/2, HSTS preload
At rest (DB)AES-256 (Supabase-managed)
At rest (object storage)AES-256 (Supabase-managed)
Key managementSupabase-managed; BYOK on Enterprise roadmap
Customer data segregation keyPer-tenant cookie HMAC keyed by per-org password hash

Compliance

QuestionAnswer
SOC 2 Type IIn progress (target Q1 2027)
SOC 2 Type IIPlanned Q3 2027
ISO 27001Not pursued
HIPAABAA available on Enterprise with PHI use case
GDPRDPA available — see DPA docs
CCPACompliant (no sale of personal data)
PCI DSSOut of scope — Stripe handles all payment data

Operational security

QuestionAnswer
Incident response planDocumented; CSM-led on Enterprise tier
Vulnerability disclosuresecurity@codivion.com, 48h ack, severity-based SLA
Penetration testingScheduled annually (next: 2026 Q4)
Security training for staffMandatory annual review
Background checksStandard for all employees with prod access
Source code reviewAll commits reviewed via GitHub PR before merge

Backups + recovery

QuestionAnswer
Backup frequencyDaily snapshots, 30-day retention
Point-in-time recovery7 days
RTO4 hours
RPO1 hour
Backup encryptionAES-256 (Supabase-managed)
Backup access controlsService-role only, audited
Disaster recovery test cadenceAnnually

Sub-processors

See DPA — current sub-processors. 14-day notice on new sub-processor additions; customer right to object.

Data subject rights

QuestionAnswer
Access requestsSelf-serve via dashboard + API export
Deletion requestsSelf-serve project delete + admin-assisted full org delete on request
Data portabilityFull DB export available on request (JSON dump)
Response SLA30 days max (GDPR-aligned)

Logging + monitoring

QuestionAnswer
Audit log retentionTeam: 90d, Enterprise: unlimited (with export)
Security event logVercel + Supabase platform logs, 30 days
AlertingSentry (errors) + uptime monitoring + PagerDuty oncall
Customer-facing audit logYes — see Audit log docs

Need something not on this list?

Email security@codivion.com with the specific question. We aim to respond within 5 business days.

Was this page helpful?

Last updated August 10, 2026