Trust

What we can show you, and what we cannot yet.

Both products exist to produce evidence, so this page is written the same way. Everything below is either in place today or stated as not in place. No third party security attestation has been completed, and none is in progress. We will say so here until one has.

01

Separation is in the database, not in the screen.

Access rules are row level security policies in PostgreSQL. The database evaluates them on every query. An interface bug cannot widen those rules because the interface is not what grants access.

Automated checks replay the separation rules and report any drift. The same checks run after every change to the application.

02

Every access is written before the decision.

An access attempt is recorded first, then the decision is recorded. That is why a refused attempt exists in the record. These records cannot be edited or deleted by anyone, including us, because the tables accept inserts only.

This also means a mistake cannot be erased. It can only be corrected by a new entry. That is a deliberate trade: the correction and the record it corrects both remain visible.

03

Where the data sits.

The applications are hosted on Supabase and use PostgreSQL. Counterline and Sidefile are in separate projects that share nothing. Data for United States customers sits at rest in the United States.

Files sit in a separate object store. They are reachable only through a function that checks the caller's permission before handing over anything. We hold no copy outside that store. The applications have no data warehouse, no analytics pipeline and no third party tracking.

04

What is not in place today.

There is no SOC 2 attestation, and none is in progress. There is no ISO certification. No penetration test report is available yet. There is no single sign on yet, and there is no published uptime history.

A business associate agreement is available where required. A data processing addendum is available. Anything on this list will move to the section above on the day it becomes true, with the date.

05

Getting your data out.

You can take a full export at any time, in an open format, without conditions, without an exit fee and without asking why.

The export includes the ledger and the register, because a record you cannot take with you is not a record you own.

Security contact

Ask us directly.

A security questionnaire is answered in writing by the same person who writes the software, with no sales intermediary.