Security

Last updated: February 22, 2026

GetDemand.ai is built with security at every layer. Your sales data, customer information, and business intelligence are protected by enterprise-grade security controls and privacy-first operating practices.

Encryption

  • โ€ขTLS 1.3 encryption for all data in transit
  • โ€ขAES-256 encryption for data at rest
  • โ€ขEncrypted database backups stored in geographically separate regions

Infrastructure

  • โ€ขHosted on Vercel (provider publishes security attestations, including SOC reports)
  • โ€ขDatabase on Supabase (provider security controls plus row-level security support)
  • โ€ขAll infrastructure runs on AWS with ISO 27001 certification
  • โ€ขAutomatic failover and redundancy across availability zones

Access Control

  • โ€ขRole-based access control (RBAC) for team members
  • โ€ขTenant-level data isolation โ€” your data is never accessible to other accounts
  • โ€ขSession management with automatic timeout and single-session enforcement
  • โ€ขOAuth 2.0 and email/password authentication via Supabase Auth

Monitoring & Audit

  • โ€ขReal-time monitoring of platform health and security events
  • โ€ขAudit logs for account access and data changes
  • โ€ขAutomated alerting for anomalous access patterns
  • โ€ขRegular dependency scanning for known vulnerabilities

Compliance

  • โ€ขSOC 2-aligned security practices and controls
  • โ€ขGDPR-ready privacy workflows and data processing terms support
  • โ€ขHIPAA-ready safeguards for protected health information use cases (see HIPAA page)
  • โ€ขStandard Contractual Clauses (SCCs) available/used where applicable for cross-border transfers

Incident Response

  • โ€ขDocumented incident response plan with defined escalation procedures
  • โ€ขTarget notification timelines based on applicable law and contract obligations (including GDPR timelines where applicable)
  • โ€ขPost-incident review and remediation for every security event
  • โ€ขRegular tabletop exercises to test response procedures

AI Data Processing

  • โ€ขAI agent processing uses OpenAI and Anthropic APIs with data processing agreements in place.
  • โ€ขYour data is not used to train third-party AI models. Both providers offer zero data retention for API usage.
  • โ€ขAI-generated content (emails, quotes, research) is stored in your account and is not shared across tenants.

Third-Party Subprocessors

ProviderPurposeLocation
VercelApplication hosting and CDNUnited States
SupabaseDatabase, authentication, storageUnited States
StripePayment processingUnited States
ResendTransactional email deliveryUnited States
OpenAIAI agent processingUnited States
AnthropicAI agent processingUnited States

Vulnerability Reporting

If you discover a security vulnerability, please report it responsibly:

  • โ€ขEmail: security@getdemand.ai
  • โ€ขInclude a description of the vulnerability, steps to reproduce, and potential impact.
  • โ€ขWe will acknowledge receipt within 48 hours and provide a remediation timeline.
  • โ€ขPlease do not publicly disclose the vulnerability until we have addressed it.