Security & Trust

Security and trust

How we keep your audits, reports, and credentials safe — and what is actually implemented in the product today.

Pillars

Defense in depth.

Subprocessors

Who touches your data.

NamePurposeData shared
Vercel
Application hosting + edge networkRequest metadata, deploy artifacts
Supabase
Postgres database + auth + storageAccount data, audit artifacts, reports
Stripe
Payment processingBilling metadata, Stripe customer ids (no raw card data)
Resend
Transactional emailRecipient email, subject, template ids
Sentry
Error tracking (when DSN configured)Stack traces, structured event tags
Inngest
Durable audit executionEvent payloads with ids only, not full records
Jina Reader
Primary page extraction for auditsPublic URL requested and extracted text/metadata
Google PageSpeed Insights
Lab performance metricsAudited public URL sent to the PSI API
OpenAI
Report reasoning (default tier)Extracted page content for the audited URL

FAQ

Common questions.

We do not hold a SOC 2 Type II report today. If your procurement process requires a security questionnaire or bridge materials, email security@pagereflect.com and we will respond with what we can share under NDA.

Need something not listed here?

Security questionnaires, architecture diagrams, and vendor details are available on request.

Email security@pagereflect.com