At a glance
Security practices
Encryption at rest & in transit
All data encrypted with AES-256 at rest. TLS 1.3 for all network connections. Stripe handles all payment data — we never see card numbers.
Identity verification
Stripe Identity verifies your licence + selfie before issuing your IDP. Identity documents are deleted within 30 days of verification.
Access controls
Row-Level Security on every database table, enforcing isolation between customers and staff. Privileged admin actions are written to an append-only audit log.
Two-factor authentication
The backend supports TOTP-based two-factor authentication (with recovery codes); in-account enrolment is being rolled out.
Vulnerability disclosure
We publish a security.txt and aim to acknowledge good-faith security disclosures within 24 hours.
Backup & recovery
Daily encrypted database backups are managed by our infrastructure provider (Supabase), so data can be restored in the event of a failure.
Compliance & certifications
RoadSeal IDP documents follow the format defined by the United Nations road traffic treaties — the 1949 Geneva Convention on Road Traffic and the 1968 Vienna Convention on Road Traffic. The full treaty texts are available from the UN Treaty Collection. How we verify the claims on this site is documented in our Editorial Policy.
| Framework | Status | Last reviewed |
|---|---|---|
| GDPR (Article 17, 20, 25) | Compliant | Q1 2026 |
| CCPA / CPRA | Aligned | Q1 2026 |
| UK Data Protection Act 2018 | Compliant | Q1 2026 |
| PCI-DSS (via Stripe) | Level 1 inherited | Q4 2025 |
| SOC 2 Type II | In progress (Q4 2026) | — |
| ISO 27001 | Planned (2027) | — |
Sub-processors
We work with these vendors to operate RoadSeal. Each has signed a DPA aligned with our privacy policy. Last updated April 2026.
| Vendor | Purpose | Data residency |
|---|---|---|
| Stripe | Payment processing & identity verification | USA / Ireland |
| Supabase (PostgreSQL) | Application database + auth | EU (Frankfurt) |
| Cloudflare Pages | Static hosting + CDN | Global edge |
| Resend | Transactional email delivery | USA |
| Anthropic (Claude API) | AI chat assistant — when enabled by user | USA |
| Trustpilot | Review collection — opt-in | EU (Denmark) |
| Google (GA4 + Maps) | Analytics + address lookup — consent-gated | USA + Global |
Security roadmap
We're an early-stage company building toward formal certification. Below is an honest picture of where we are and what's planned — we don't claim audits we haven't completed.
SOC 2 Type II
Independent attestation of security controls over time, once the Type I milestone is complete.
SOC 2 Type I
First independent attestation of our security posture at a point in time.
Row-Level Security across the database
Every application table enforces row-level isolation between customers and staff, with privileged actions written to an append-only audit log.
Payments & identity handled by Stripe
Card data and identity verification are processed by Stripe (PCI-DSS Level 1); we never store card numbers, and identity documents are deleted within 30 days of verification.
Reporting concerns
Security vulnerability
Email [email protected] with details. PGP key available at /security.txt. We respond within 24 hours.
Privacy / GDPR request
Email [email protected] or use the self-service portal for data export and deletion. 30-day SLA.
Compliance / press
Email [email protected] for legal inquiries, audit cooperation, or press requests for compliance details.
Live status
Real-time uptime, incidents, and maintenance windows on status.roadseal.co.