Every table carries a row-level security policy keyed on your organization. The app queries as the signed-in user, so a bug in a page cannot cross a tenant boundary.
TLS with HSTS on every request, encrypted storage under the database, and your cloud credentials encrypted with a key the database never sees.
Session cookies are HttpOnly, Secure and SameSite. A strict content security policy and a no-framing rule contain what a script injection could do.
Approvals, status changes and uploads are written to an activity log with the person and the timestamp. Assessors ask for this first; you already have it.
Export the readiness report or the JSON at any time. If you stop paying, the workspace goes read-only and nothing is deleted.
We do not yet hold our own SOC 2 report or a third-party penetration test. Both are listed below, with what we are doing about them.
Tenant isolation
AuditSquire is multi-tenant: many organizations share one database. The property that matters most is that one of them can never read another's evidence, and that property is not left to application code.
One exception exists and is worth naming: the code that records subscription changes reported by our payment provider uses a server-only administrative client, because those events arrive with no user session. It touches billing state only and never reads or writes a compliance record.
Encryption
Sessions & browser
Most damage to a web application starts with a script that should not be running. The session and the response headers are configured to make that script as useless as possible.
frame-ancestors 'none'), which closes clickjacking against the dashboard.Who can see your workspace
| Owner | Everything, including billing and the org itself. An organization can never be left without one. |
|---|---|
| Admin | Runs the program: controls, policies, evidence, audits, team. |
| Contributor | Works across the program without administering it. |
| Manager | Company-wide status read-only, plus full write access to the controls and tasks they own. |
| Member | Their own tasks and the policies they must acknowledge. Nothing else. Free. |
| Auditor | Read-only everywhere, plus the ability to raise evidence requests. Free. |
Roles are enforced by database policy, not by hiding buttons. A member cannot open the controls page by typing its address, and an auditor cannot change a status by crafting a request.
AuditSquire staff can access your workspace.
AuditSquire is sold and set up by us or by a managed service provider working with you. A small number of named operator accounts can open any organization to onboard and support it. That access is granted in the database by hand, cannot be self-assigned through the product, and every write those accounts make lands in your activity log under their name, the same as anyone else's. If your policy requires that we not have standing access, say so during onboarding.
Auditor access
The auditor role exists so an external assessor can read the evidence where it lives rather than receiving screenshots. It is read-only everywhere and can do exactly one thing beyond reading: raise an evidence request against a requirement, which the owning person answers by attaching what is already on file. Each request records who asked, who answered, what was attached and when.
The activity log is written to on every approval, status change and upload, with the actor and a timestamp, and assessors are shown it directly. The readiness report is printable and written to be read by an assessor, so both sides start from the same numbers.
Your data, your exit
Subprocessors
| Provider | Purpose | What it sees | Location |
|---|---|---|---|
| Vercel | Application hosting and TLS termination. | Everything served by the app passes through it. Nothing is stored there. | United States |
| Supabase (on AWS) | Postgres database, authentication, and evidence file storage. | All customer records and uploaded evidence, encrypted at rest. | AWS us-east-2 (Ohio) |
| Resend | Transactional email for team invitations. | Recipient address, inviter name, organization name. | United States |
| Anthropic | Plain-English explanations of uploaded scan reports. | Individual findings with hostnames and IP addresses replaced by placeholders before the request leaves. Never the uploaded file itself. | United States |
| Stripe | Subscription billing, when a paid plan is activated. | Card details are entered on Stripe's hosted checkout and never touch AuditSquire. | United States |
Scan explanations deserve a sentence more. When you upload a vulnerability scan, the parsed findings are sent to Anthropic's API to be rewritten in plain language. Hostnames and IP addresses are replaced with placeholders before the request leaves, and the model is never the source of a number: CVE identifiers, scores and counts come from the parser and are rendered directly. This step is optional and runs only when you upload a scan.
Independent review
In August 2026 an external reviewer performed a black-box security assessment of the served application on an authenticated session: response headers, cookie flags, client-side exposure of the session, and the client bundle. It raised findings on session cookie flags and missing response headers. Both were remediated within the week, and the review's remaining recommendation, an audit of every row-level policy, was carried out at the same time.
In September 2026 we ran a full internal security assessment ourselves: every server action, every row-level policy and database function, every upload path and every outbound request, cross-checked against the live configuration. It found four issues we rated High, all within the tenant boundary rather than across it, and fixed them the same day along with the rest of the list. It is a white-box review by the people who built the system, so it is not a penetration test and we do not present it as one; it is the starting document we hand to the independent tester.
The database platform's own security advisor is run against production. As of the date at the top of this page it reports no table without row level security and no policy open to anonymous users. Its remaining notes describe the tenancy and workflow functions being callable by signed-in users, which is how they are designed to work, and one billing-events table that no signed-in user can read.
Not yet
A trust page that lists only strengths is a marketing page. These are the gaps a careful buyer will find, listed so you do not have to.
Our own SOC 2 report
AuditSquire has not completed a third-party audit of itself. We run our own compliance program inside AuditSquire, with the same rules that apply to you: no control is credited without current evidence. We will share our current readiness report with you under NDA on request, and this page will link the SOC 2 report when it exists.
A third-party penetration test
An external black-box review of the served application in August 2026 and a full internal white-box assessment in September 2026 were both remediated in full. Neither is a penetration test, and we do not describe them as one. The independent engagement is scoped, with a dedicated test environment and rules of engagement written, and is the next thing we commission. Its attestation letter will be linked here.
A documented backup restoration test
Backups are the database provider's. We have not yet performed and documented a restoration drill of our own, and we will not claim a recovery time until we have.
Reporting a vulnerability
If you find a security problem in AuditSquire, email hello@auditsquire.com with “Security” in the subject. It reaches Chris Foster, the founder, not a queue. You will get a human reply, a fix or a timeline for one, and credit if you want it. We ask that you avoid accessing another organization's data if you find a way to; report it and we will reproduce it in a test tenant.