Clear answers about how Secured Roots protects public records.
Security and procurement reviews should not require a scavenger hunt. This center describes the controls in the service today and the providers that help us operate it.
Last updated August 6, 2026Security at the data boundary
Organization data is isolated in PostgreSQL with row-level security based on the signed-in user and active organization membership. Sensitive incident records have tighter role rules. Platform administration is separate from customer roles and requires multi-factor authentication, short-lived administrative sessions, and append-only audit records.
Organizations keep control
Authorized users can export organization records and audit materials. A lapsed trial or subscription becomes read-only rather than locking an organization out of its own compliance records. Card information is entered only in Stripe-hosted pages and never passes through Secured Roots servers.
Operational transparency
Webhook failures, email delivery events, application errors, scheduled jobs, and platform health are monitored in the internal console. Backup availability and restore exercises are recorded as append-only evidence. We do not claim a certification or independent audit that has not been completed.
Need a security review?
Send a questionnaire or procurement request to gabe.holcomb@securedroots.com. Please do not send passwords, authentication codes, incident evidence, or other sensitive records by ordinary email.