Trust Center

How we approach security and compliance at InnoBee, who processes data on our behalf, and how to request our compliance documentation.

We believe a security page should only say what's actually true. The practices below describe programs we genuinely run — not certifications we hold. We don't claim SOC 2 or similar formal certifications unless and until we actually obtain them, and we won't publish an audit or pentest cadence as an established track record before it is one.

Internal production audit framework

We evaluate our stack against a structured, 13-layer internal audit covering authentication, database, security, hosting, deployment, monitoring, scaling, recovery, and more. This is an active internal practice — ask us for our current audit status if you need it for procurement.

Incident response plan

We maintain a written incident response plan covering severity classification, roles, containment, and communication, with every incident followed by a blameless post-mortem within 48 hours.

Report a vulnerability

Found a security issue? Email security@innobee.buzz. We ask that you report privately and give us reasonable time to respond before any public disclosure.

Data Processing Agreement

Organizations that need a DPA for GDPR Article 28 purposes can review and request ours directly — see our Policies & Guidelines page.

Subprocessors

Supabase
Database, authentication, and file storage infrastructure
Active
Stripe
Payment processing, escrow, and payout handling
Active
Resend
Transactional email delivery
Active
Anthropic
AI features (InnoBee Queen)
Active

Request our compliance documentation

Enterprise customers can request our current production audit status, penetration test summary (once available), Data Processing Agreement, and subprocessor details for procurement — typically under a mutual NDA.