We run small businesses' livelihoods through this product. Here's how we treat that responsibility.
Tenant isolation
Every row in every table carries an organization_id, enforced by Postgres row-level security. A user can only ever read or write rows owned by an organization they belong to. Service-role access is restricted to vetted server functions and webhook handlers.
Authentication & roles
Email + password and Google OAuth, with email verification required. Roles (site_admin, org_admin, member) live in a separate user_roles table and are checked through SECURITY DEFINER functions, eliminating recursive-RLS pitfalls and client-side role spoofing.
Encryption
All traffic is HTTPS / TLS 1.2+. Data at rest is encrypted with AES-256. Customer secrets (Stripe keys, webhook secrets, OAuth tokens) live in our managed secret store and are never written to client bundles.
Backups & recovery
Automated daily Postgres backups with a 7-day point-in-time-restore window. Backups are encrypted and replicated across availability zones. We rehearse restore drills quarterly.
Payment data
Card details never touch our servers. Ignite Up uses Stripe's PCI-DSS Level 1 certified embedded checkout — your subscription, invoices and saved cards are stored on Stripe.
Audit trail
Pricing catalog changes, statement approvals, expense decisions, and Stripe sync events are all written to append-only logs visible to site_admin. Every row records the actor, timestamp, and prior state.
Responsible disclosure
Found something? Email security@igniteup.app. We acknowledge within 1 business day and credit reporters in our changelog.
Need a SOC 2 report, DPA, or custom security questionnaire response?
Get in touch.