Data Security

At OnRecord, we know that your company metrics, runway, burn rate, and investor updates are confidential. We build with strict data isolation, modern encryption, and hardened payment infrastructure.

Data isolation & confidentiality

Database-enforced isolation: Every company record and monthly update is guarded by database-level Row-Level Security (RLS). All queries require an authenticated session and are strictly locked to your account.

You own your data: We do not sell, rent, or monetize your company data. Your numbers and notes are used solely to generate and format your updates.

Stateless AI processing: When our AI drafts summaries or tidies bullet points, requests are processed statelessly via secure enterprise API gateways. Your financial metrics and proprietary updates are never used to train public AI models.

Encryption & infrastructure

Encrypted in transit: All data sent between your browser and OnRecord is encrypted using modern TLS (HTTPS), protecting against interception.

Encrypted at rest: All application databases and backups are encrypted at rest using industry-standard AES-256 encryption.

Resilient cloud infrastructure: Hosted on global, enterprise-grade cloud infrastructure with automated backups and continuous health monitoring.

Payment & billing security

PCI-DSS Level 1 compliant billing: All payments, subscriptions, and card details are handled directly by Stripe.

Zero card storage: OnRecord servers never receive, process, or store credit card numbers, expiration dates, or security codes.

Signed webhook communication: Communication between Stripe and OnRecord is cryptographically verified to prevent tampering.

Questions & responsible disclosure

If you have questions about our security practices or wish to report a security concern, please contact us at support@onrec.io.