TrustEA · SEC
Trust

Security &compliance

We are a security company — the platform runs the same controls we ask you to put around your browser fleet. This page is the honest state of our posture: what is in place today, and what is on the roadmap.

How we protect your data01 / Practices

Tenant isolation

Every table is scoped to your account at the database layer.

  • Postgres row-level security enforced on all tenant data
  • Role-based access with least privilege
  • Team workspaces isolated per account — no shared credentials

Authentication & identity

Login security is never an upsell — the free plan gets the same controls.

  • SAML SSO included on every plan
  • Multi-factor authentication support
  • OAuth sign-in with Google, GitHub, and Apple

Encryption & edge protection

All traffic is encrypted in transit and filtered at the edge.

  • TLS 1.3 with HSTS on every endpoint
  • Web application firewall and DDoS mitigation at the edge
  • Credentials and API keys held outside source control

Secure development

Security review is part of every change, not a phase.

  • Mandatory review on every change
  • Automated dependency and supply-chain scanning
  • Schema-validated inputs on every API boundary

Monitoring & incident response

Errors are tracked centrally and incidents follow a written runbook.

  • Centralized error tracking across web, worker, and browser agent
  • Documented incident-response runbook
  • Plan-level first-response targets, down to 4 hours on Enterprise

Data minimization

Extension analysis runs on public data — personal data collection stays minimal.

  • Risk analysis uses public Chrome Web Store metadata
  • GDPR Article 30 processing register maintained and reviewed
  • Data subject access requests honored
Where we stand, framework by framework02 / Compliance

GDPR

Maintained

The EU General Data Protection Regulation governs how personal data of EU residents is handled. We maintain an Article 30 record of processing activities, document a lawful basis for every processing purpose, keep a register of subprocessors, and honor data subject rights. Our Data Protection Officer is reachable at [email protected], and a data processing agreement is available to customers on request.

Read the privacy policy

Singapore PDPA

Maintained

Extension Auditor is built by Alpha CISO Pte. Ltd., a company registered in the Republic of Singapore. Our processing register and privacy program are maintained under the Personal Data Protection Act alongside GDPR, with a single register covering both.

PCI DSS

Via Stripe

Businesses that handle cardholder data must comply with the Payment Card Industry Data Security Standard. Payments for Extension Auditor are processed by Stripe, a certified PCI Level 1 service provider — card numbers never touch our servers, and we store no cardholder data.

SOC 2 Type II

In progress · Target 2026

We are working towards formal SOC 2 Type II certification as we scale our enterprise customer base. The controls described on this page are operated today; the audit formalizes them. Prospective customers can request current security documentation in the meantime.

ISO/IEC 27001

Planned

ISO/IEC 27001 certification for our information security management system is on the roadmap, following SOC 2. The same control set feeds both programs.

For your auditors03 / Evidence

Compliance evidence for your own audits

Extension governance is a control your auditors ask about. Extension Auditor maps fleet policy and monitoring evidence to SOC 2 and ISO 27001 controls, so browser-extension risk shows up in your audit file as evidence rather than a gap. Compliance mapping is available on Business and Enterprise plans.

Enterprise procurement needs answers, not a runaround. We complete vendor security assessments on request:

  • CAIQ

    Cloud Security Alliance Consensus Assessments Initiative Questionnaire

  • SIG Lite

    Standardized Information Gathering questionnaire

  • VSA

    Vendor Security Alliance questionnaire

  • Custom

    Your organization’s own security questionnaire

Questions about our security posture?

We complete vendor security questionnaires, share current documentation, and schedule security review calls with prospective customers. A data processing agreement is available on request via [email protected].

Next step

Start a free trial or book a demo — no fleet required to evaluate risk data first.