Skip to content

Security

Built to protect the contract in front of you

Not a certification page: an accurate one. Here is exactly what protects your data today, and what we do not yet claim.

Runs on infrastructure independently audited to SOC 2 Type II.

VercelNeon

In place today

Controls that are live in production, not aspirational

Infrastructure & hosting

Application hosting on Vercel, Postgres on Neon: both independently SOC 2 Type II audited at the infrastructure layer. Database backups run automatically with point-in-time recovery.

Encryption everywhere

HTTPS forced on every connection via HSTS. Sensitive stored fields, like provider credentials, get an extra AES-256-GCM envelope encryption pass before they reach the database.

Two-factor authentication

Optional TOTP-based 2FA on every account, alongside standard email/password sign-in.

Tenant isolation

Every tenant is isolated by an identifier checked on the server on every request, not just filtered in the UI.

Real-time monitoring

Application errors are tracked live through Sentry. API and authentication endpoints are rate-limited against brute-force and abuse.

Full audit trail

Every meaningful data mutation (calculations, contract edits, counterparty actions) records who did it and when.

Hardened by default

HSTS, CSP, X-Frame-Options, nosniff and a strict referrer/permissions policy on every response. Dependabot scans dependencies daily and opens a PR on any known vulnerability.

DISCLOSURE

Found something? Tell us.

Email admin@escalake.com with what you found and how to reproduce it. Give us a reasonable window to investigate and fix an issue before disclosing it publicly, and avoid accessing, modifying, or destroying data that isn't yours while testing.

The same policy is published machine-readable per RFC 9116.

GET /.well-known/security.txt
Contact: mailto:admin@escalake.com
Expires: 2027-09-03T00:00:00.000Z
Preferred-Languages: en
Canonical: https://escalake.com/.well-known/security.txt
Policy: https://escalake.com/security

Roadmap

Where we actually stand on compliance

Read our Privacy Policy for what we collect and why, and our Data Processing Agreement for how we process data on a customer's behalf.

What's certified

Nothing yet. Escalake does not hold a SOC 2, ISO 27001, or HIPAA certification itself.

What's real today

Every control above is live in production: encryption, 2FA, tenant isolation, monitoring, and audit trail all included.

What's next

SOC 2 Type II is on the roadmap as the company scales. Not yet started.

Have a security question?

Email us and we'll tell you plainly where we stand on it.