security & data

How we protect your data.

Honest, current state — not aspirational claims.

Last updated: 2026-04-27
01 — Posture

How we operate today

FAFFLY is currently in a private build phase. We are onboarding our first 20 customers as Founding Partners. This page reflects our current operational posture, not a finished compliance program.

02 — Hosting

Where your data lives

All customer data is hosted on:

Supabase (PostgreSQL + Auth) — Amazon AWS us-west-2 region
Vercel (web hosting) — global edge network with US origin
Resend (transactional email) — North America
Shopify (read-write API access scoped to your store) — per Shopify’s security standards
03 — Encryption

Encryption

Data is encrypted in transit via TLS 1.3 and at rest via AES-256, as provided by Supabase and Vercel infrastructure defaults. We do not currently operate independent encryption key management.

04 — Auth

Authentication

User authentication is handled by Supabase Auth with bcrypt password hashing. Sessions are JWT-based with 1-hour expiry.

05 — Access

Access control

All customer data tables use Postgres row-level security to enforce tenant isolation. No FAFFLY employee accesses customer data without your written consent.

06 — Compliance

Compliance posture (honest)

We are working toward SOC 2 readiness as we grow. We do not currently hold any third-party security certifications. We commit to GDPR and CCPA principles in our handling of personal data, but have not yet completed a formal compliance review. Our roadmap includes:

LLC formation and DPA template (Q2 2026)
Formal incident response process (Q3 2026)
SOC 2 Type I readiness assessment (2026)
07 — Disclosure

Reporting a security issue

Found a security issue? Email hello@faffly.co with the subject line ‘security’. We commit to acknowledging within 48 hours.

08 — Sub-processors

Sub-processors

The third-party services that process customer data on our behalf:

Provider Purpose Region Security
Supabase PostgreSQL database + auth AWS us-west-2 supabase.com/security →
Vercel Web hosting / edge Global, US origin vercel.com/security →
Resend Transactional email North America resend.com/legal/subprocessors →
Shopify Customer/discount API Per Shopify standards shopify.com/legal →

Have specific security questions for procurement?

Schedule a call →