SOC 2 Type II
InfrastructureService Organization Control 2 — Trust Services Criteria
- Data hosted on Supabase, which maintains SOC 2 Type II certification
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Row-Level Security (RLS) policies on all database tables
- Audit logging for sensitive operations
- Access controls via role-based authentication (RBAC)
- Regular vulnerability assessments
ISO 27001
Information SecurityInformation Security Management System (ISMS)
- Authentication system with secure password hashing (bcrypt via Supabase Auth)
- Role-based access control with user_roles table and security-definer functions
- Session management with automatic expiration
- Data classification: public, internal, and confidential tiers
- Incident response procedures documented and tested
- Security-definer functions prevent privilege escalation in RLS policies
ISO 42001
AI ManagementArtificial Intelligence Management System
- AI transparency: all AI features clearly disclose when content is AI-generated
- Model documentation: Google Gemini 2.5 Pro, OpenAI GPT-4, and Hugging Face models used
- Human oversight: users must review and approve all AI outputs before use
- AI content is not used for automated decision-making affecting individuals
- Bias monitoring: AI outputs are not used for hiring, lending, or other high-stakes decisions
- Data minimization: only necessary prompts are sent to AI providers
- AI features include disclaimers that outputs may contain errors and should be verified
PCI-DSS
Payment SecurityPayment Card Industry Data Security Standard
- All payment processing delegated to Stripe (PCI-DSS Level 1 Service Provider)
- No payment card numbers, CVVs, or sensitive authentication data stored on our servers
- Payment forms rendered via Stripe's secure iframes (Stripe.js / Elements)
- Tokenized payment methods — only Stripe tokens are transmitted
- No direct access to cardholder data environment (CDE)
- SAQ A eligible: all payment pages fully outsourced to Stripe
GDPR
Data ProtectionGeneral Data Protection Regulation (EU)
- Lawful basis for processing documented (consent, contract, legitimate interest)
- Cookie consent banner with granular opt-in/opt-out controls
- Right to Access: users can request a copy of their data
- Right to Erasure: account deletion with 30-day data purge
- Right to Data Portability: data export in machine-readable format
- Right to Rectification: users can update their profile data
- Data Protection Officer contactable at privacy@streamwalkerscorp.com
- Privacy Policy clearly discloses all third-party data processors
- Data Processing Agreements (DPAs) in place with sub-processors
CCPA
Consumer PrivacyCalifornia Consumer Privacy Act
- Right to Know: users can request disclosure of data collected
- Right to Delete: users can request deletion of personal information
- Right to Opt-Out: we do not sell personal information
- Right to Non-Discrimination: equal service regardless of privacy choices
- Privacy Policy includes required CCPA disclosures
- 'Do Not Sell My Personal Information' — N/A: we do not sell data
CAN-SPAM
Email ComplianceControlling the Assault of Non-Solicited Pornography and Marketing Act
- All marketing emails include clear sender identification
- Physical mailing address included in email footers
- One-click unsubscribe mechanism in all marketing communications
- Opt-out requests honored within 10 business days
- No deceptive subject lines or misleading header information
- FlyByMe flyer emails comply with CAN-SPAM requirements