inflecto.ai

Security & Compliance

Inflecto.ai processes publicly available government and regulatory data. No personally identifiable information is collected or stored.

Data Architecture

Processing region
United States (Vercel iad1 — Washington DC)
Database
Supabase (Postgres) — US East region
Hosting
Vercel — serverless, US regions only
Data transport
HTTPS/TLS 1.2+ for all ingestion and API calls
API authentication
Bearer token (INFLECTO_API_KEY) — per-customer, rotatable

Data Sources & Ownership

Inflecto ingests exclusively from 26 publicly available government and regulatory data sources. No proprietary, licensed, or personally identifiable information is collected or stored.

View full data source catalog →

Processing & Retention

Ingestion frequency
Daily to monthly, depending on source cadence
Data retention
Signal records retained indefinitely for historical analysis
Raw source data
Not retained — only normalized, classified records are stored
PII handling
No PII collected. Public records only.
Backups
Supabase managed backups — point-in-time recovery enabled
Data deletion
Customer account data deleted within 30 days of contract termination upon request

Access Controls

Dashboard access
Password-protected — invite-only during early access
API access
Bearer token authentication — per-customer keys
Database access
Supabase RLS enabled — deny-all default, row-level policies per endpoint
Internal access
Service role key used only in server-side API routes — never exposed to client
Secret management
Environment variables via Vercel — not stored in source code

Compliance Posture

SOC 2

In Progress

SOC 2 Type II audit is in progress. Target completion: 2026.

GDPR / CCPA

Not Applicable

Inflecto processes only publicly available U.S. government data. No EU personal data or California consumer data is collected or processed.

Data Residency

US Only

All data is processed and stored in U.S. regions. No data is transferred outside the United States.

Vulnerability Disclosure

Security researchers can report suspected vulnerabilities to security@inflecto.ai. Include affected URLs, reproduction steps, and any relevant logs or screenshots.

Questions about our security posture?

security@inflecto.ai·Request Early Access →