Trust center

Clear answers about how Secured Roots protects public records.

Security and procurement reviews should not require a scavenger hunt. This center describes the controls in the service today and the providers that help us operate it.

Last updated August 6, 2026
Security practicesArchitecture, access controls, monitoring, recovery, and incident reporting.Privacy noticeWhat information is processed, why it is needed, and the choices organizations retain.SubprocessorsThe service providers used for hosting, payments, email, and assisted drafting.AccessibilityOur WCAG 2.2 AA target, current testing approach, and support channel.Procurement summaryA concise, printable vendor and security overview for purchasing files.

Security at the data boundary

Organization data is isolated in PostgreSQL with row-level security based on the signed-in user and active organization membership. Sensitive incident records have tighter role rules. Platform administration is separate from customer roles and requires multi-factor authentication, short-lived administrative sessions, and append-only audit records.

Organizations keep control

Authorized users can export organization records and audit materials. A lapsed trial or subscription becomes read-only rather than locking an organization out of its own compliance records. Card information is entered only in Stripe-hosted pages and never passes through Secured Roots servers.

Operational transparency

Webhook failures, email delivery events, application errors, scheduled jobs, and platform health are monitored in the internal console. Backup availability and restore exercises are recorded as append-only evidence. We do not claim a certification or independent audit that has not been completed.

Need a security review?

Send a questionnaire or procurement request to gabe.holcomb@securedroots.com. Please do not send passwords, authentication codes, incident evidence, or other sensitive records by ordinary email.