Security & Trust Center
SaaS Factory is built for enterprises that have security review requirements. This page documents our security controls, compliance posture, sub-processor list, and how to access compliance documentation for procurement.
Last updated: August 2026 · Questions? security@saas-factory.ai
Security Controls
Built to pass your security review
Security is not a feature we bolt on. Every product built on SaaS Factory inherits these controls from the platform infrastructure from day one.
Encryption at Rest
AES-256-GCM encryption on all sensitive fields — GitHub tokens, API keys, PII. Neon Postgres volumes are encrypted at the storage layer.
Encryption in Transit
TLS 1.3 enforced on all connections. HSTS with 1-year max-age. Certificate pinning on mobile SDKs.
Access Control & RBAC
Role-based access on every API endpoint. Project-level ownership model. Row-Level Security (RLS) in Postgres prevents one customer's data leaking into another's.
Immutable Audit Log
Every state-changing operation is written to an append-only audit log with actor, timestamp, and resource ID. 2-year retention for SOC 2.
Vulnerability Management
Automated dependency scanning on every PR. OWASP Top-10 checklist validated by the security agent. CVE triage SLA: 24 h critical, 72 h high.
Vendor Security Review
All sub-processors have DPAs in place. Third-party access is reviewed quarterly. Anthropic, Vercel, Neon, Stripe, GitHub, Temporal Cloud and Resend hold SOC 2 reports.
Data Isolation
Customer data isolation via Postgres RLS. Enterprise customers get a dedicated database namespace. No co-mingling of production data between customers.
Backups & Recovery
Automated daily snapshots with 30-day retention. Point-in-time restore to any second in the last 24 hours. Tested recovery quarterly.
Security Incident Response
Documented IR plan with <1 h detection, <4 h containment targets. Affected customers notified within 72 h per GDPR Article 33.
Infrastructure Hardening
Vercel edge network with WAF, DDoS mitigation, and rate limiting. Neon Postgres isolated VPC. No direct internet access to database layer.
Uptime & Status
Every product built on SaaS Factory gets its own live status page.
SOC 2 Trust Service Criteria
All five trust categories covered
Our SOC 2 Type II audit covers the full AICPA Trust Service Criteria framework. Below are the criteria our controls are organised around. Measured status from our own continuous audits follows.
Measured control status
From SaaS Factory's own continuous automated audits of this platform — not a third-party attestation.
| Framework | Score | Passing | Partial | Needs attention | Assessed | Status |
|---|---|---|---|---|---|---|
| SOC 2 | 96% | 12 | 1 | 0 | 8 Jul 2026 | Partial |
| GDPR | 75% | 9 | 0 | 3 | 8 Jul 2026 | Needs attention |
| ISO 27001 | 91% | 10 | 0 | 1 | 8 Jul 2026 | Needs attention |
| HIPAA | 100% | 10 | 0 | 0 | 8 Jul 2026 | Operational |
Sub-Processors
Our third-party data processors
All sub-processors hold DPAs with SaaS Factory and have been reviewed for SOC 2 or equivalent certification. We maintain this list and notify customers of changes with 30 days’ notice.
Anthropic
- Purpose
- AI model inference — pipeline agent reasoning
- Region
- USA
- Certifications
- SOC 2 Type II
- DPA
- In place
Vercel
- Purpose
- Application hosting, serverless runtime, CDN
- Region
- Global (USA primary)
- Certifications
- SOC 2 Type IIISO 27001
- DPA
- In place
Neon
- Purpose
- Postgres database hosting
- Region
- USA / EU
- Certifications
- SOC 2 Type II
- DPA
- In place
Stripe
- Purpose
- Payment processing, subscription billing
- Region
- USA / EU
- Certifications
- SOC 2 Type IIPCI DSS Level 1
- DPA
- In place
GitHub
- Purpose
- Source control, CI/CD, PR pipeline
- Region
- USA
- Certifications
- SOC 2 Type IIISO 27001
- DPA
- In place
Temporal Cloud
- Purpose
- Workflow orchestration, cron scheduling
- Region
- USA / EU
- Certifications
- SOC 2 Type II
- DPA
- In place
Resend
- Purpose
- Transactional email delivery
- Region
- USA
- Certifications
- SOC 2 Type II
- DPA
- In place
To be notified of sub-processor changes, email security@saas-factory.ai and ask to join our sub-processor change notification list.
Compliance Documents
Documentation for your procurement team
The documents below are typically required during enterprise security reviews. Reach out to get started — we aim to turn a request around within 1 business day.
Data Processing Agreement (DPA)
Standard DPA based on the EU Standard Contractual Clauses (SCCs). Covers GDPR Article 28 controller–processor obligations. Pre-signed version available for download.
Business Associate Agreement (BAA)
HIPAA Business Associate Agreement available for Enterprise customers operating in healthcare verticals. Contact our compliance team to execute.
Security Questionnaire (CAIQ / SIG Lite)
Pre-filled CSA CAIQ and SIG Lite questionnaires for security review programmes. Last updated August 2026.
Privacy Policy
GDPR-compliant privacy policy covering data collection, processing, retention, sub-processors, and data subject rights.
Data Residency
Your data stays where regulations require
Choose your database region at project creation. Data at rest never leaves your selected region. Backups are stored in the same region.
UK hosting is governed by UK GDPR. For EU personal data with a strict EU-residency requirement, choose Frankfurt — UK transfers rely on the UK adequacy decision rather than being inside the EEA.
Additional regions available on Enterprise plans. Contact sales@saas-factory.ai for dedicated infrastructure.
Responsible Disclosure
Security vulnerability reporting
We take security reports seriously. If you discover a vulnerability, please report it responsibly and we will work with you to address it quickly.
Ready to complete your security review?
Our security team is ready to answer questionnaires, provide compliance documentation, and execute DPAs and BAAs for Enterprise procurement. Typical turnaround: 1 business day.