Where things stand today
AirQuote is currently operated as a small/single-operator business. We don't yet have a dedicated 24/7 security team, formal SOC 2 certification, or a penetration-testing program. We'd rather tell you that plainly than overstate our maturity — factor it into your own risk assessment, and this page will be updated as that changes.
Security measures in place
- All data is transmitted over encrypted connections (TLS/HTTPS).
- Access to production systems is restricted and authenticated.
- Customer data is logically separated by account — multi-tenant isolation is enforced at both the database and application layer, so one business's data is never visible to another.
- Automated and scheduled processes that trigger customer-facing actions (like reminder emails or renewal checks) are authenticated with server-side secrets, not left open.
- Error monitoring and crash reporting run continuously so problems surface quickly.
Infrastructure & subprocessors
AirQuote is built on established infrastructure providers rather than self-hosted systems, so the underlying platforms carry their own security programs:
- Supabase — database, authentication, and file storage.
- Netlify — application hosting and infrastructure.
- Stripe — payment processing (AirQuote never stores full card numbers).
- Resend & Twilio — email and SMS delivery.
- Anthropic — AI-assisted features, as disclosed in the Privacy Policy.
How we respond to an incident
AirQuote follows a defined internal incident response process covering detection, containment, investigation, notification, recovery, and post-incident review. In short:
- Reports are triaged and classified for severity within the first 15–30 minutes.
- Compromised credentials are rotated immediately; affected accounts can be suspended; bad deployments are rolled back.
- If personal data was or may have been exposed, affected business customers are notified without undue delay so they can meet their own downstream obligations — consistent with the notification commitment in our DPA.
- Every incident gets a post-incident review within 5 business days of resolution, with concrete follow-up actions tracked to completion.
Reporting a security concern
If you believe you've found a security issue affecting AirQuote, please email legal@reaper.software with details. We review all reports.