Trust Center

Trust & Security

How DBA Check handles security, privacy, and legal transparency.

Last updated: February 18, 2026

Security model

  • All API keys stay server-side and are never exposed in the browser.
  • Company-level isolation is enforced with Supabase RLS policies.
  • Rate limiting and audit logging are enabled on critical routes.
  • Data in transit uses TLS and storage is encrypted by infrastructure providers.

Privacy & retention

  • Extracted contract text is automatically deleted after 30 days.
  • Only metadata and scoring results are retained for reporting and trend analysis.
  • You can export data (CSV) and permanently delete your account from Settings.
  • PII is sanitized before AI analysis where possible.

Key subprocessors

These providers process data on behalf of DBA Check.

ProviderPurposeRegion
SupabaseAuthentication, PostgreSQL data, file storageEU
VercelApplication hosting and edge deliveryEU/Global
AnthropicAI contract analysisUS/EU endpoints
StripeBilling and subscription processingGlobal
ResendTransactional emails (reports, invites)EU/US
UpstashRate limiting and cacheEU/Global

Incident response

  1. 1Detection and triage are initiated as soon as a potential incident is identified.
  2. 2Access is contained and affected systems are isolated where necessary.
  3. 3Root cause analysis and remediation are performed with full audit logging.
  4. 4If required, customers are notified with scope, impact, and recovery actions.

Contact & legal

For privacy, security, or legal questions, contact our team directly.