AirQuote

How we protect
your data.

A plain-language summary of the security practices and incident-response process behind AirQuote. For the legal version, see the Data Processing Agreement.

Where things stand today

AirQuote is currently operated as a small/single-operator business. We don't yet have a dedicated 24/7 security team, formal SOC 2 certification, or a penetration-testing program. We'd rather tell you that plainly than overstate our maturity — factor it into your own risk assessment, and this page will be updated as that changes.

Security measures in place

  • All data is transmitted over encrypted connections (TLS/HTTPS).
  • Access to production systems is restricted and authenticated.
  • Customer data is logically separated by account — multi-tenant isolation is enforced at both the database and application layer, so one business's data is never visible to another.
  • Automated and scheduled processes that trigger customer-facing actions (like reminder emails or renewal checks) are authenticated with server-side secrets, not left open.
  • Error monitoring and crash reporting run continuously so problems surface quickly.

Infrastructure & subprocessors

AirQuote is built on established infrastructure providers rather than self-hosted systems, so the underlying platforms carry their own security programs:

  • Supabase — database, authentication, and file storage.
  • Netlify — application hosting and infrastructure.
  • Stripe — payment processing (AirQuote never stores full card numbers).
  • Resend & Twilio — email and SMS delivery.
  • Anthropic — AI-assisted features, as disclosed in the Privacy Policy.

How we respond to an incident

AirQuote follows a defined internal incident response process covering detection, containment, investigation, notification, recovery, and post-incident review. In short:

  • Reports are triaged and classified for severity within the first 15–30 minutes.
  • Compromised credentials are rotated immediately; affected accounts can be suspended; bad deployments are rolled back.
  • If personal data was or may have been exposed, affected business customers are notified without undue delay so they can meet their own downstream obligations — consistent with the notification commitment in our DPA.
  • Every incident gets a post-incident review within 5 business days of resolution, with concrete follow-up actions tracked to completion.

Reporting a security concern

If you believe you've found a security issue affecting AirQuote, please email legal@reaper.software with details. We review all reports.