At a glance
Security practices
Encryption at rest & in transit
All data encrypted with AES-256 at rest. TLS 1.3 for all network connections. Stripe handles all payment data — we never see card numbers.
Access controls
Row-Level Security on every database table, enforcing isolation between customers and staff. Privileged admin actions are written to an append-only audit log.
Vulnerability disclosure
We publish a security.txt and a disclosure policy, and aim to acknowledge good-faith reports within three business days.
Backup & recovery
Daily encrypted database backups are managed by our infrastructure provider (Supabase), so data can be restored in the event of a failure.
Compliance & certifications
RoadSeal IDP documents follow the format defined by the United Nations road traffic treaties — the 1949 Geneva Convention on Road Traffic and the 1968 Vienna Convention on Road Traffic. The full treaty texts are available from the UN Treaty Collection. How we verify the claims on this site is documented in our Editorial Policy.
| Framework | Status | Assessed by | Last reviewed |
|---|---|---|---|
| GDPR (Article 17, 20, 25) | Self-assessed | RoadSeal | Q1 2026 |
| CCPA / CPRA | Self-assessed | RoadSeal | Q1 2026 |
| UK Data Protection Act 2018 | Self-assessed | RoadSeal | Q1 2026 |
| PCI-DSS (via Stripe) | Level 1 inherited | Stripe's assessor | Q4 2025 |
| SOC 2 Type I | In progress (Q4 2026) | Independent auditor | — |
| SOC 2 Type II | Planned (2027) | Independent auditor | — |
| ISO 27001 | Planned (2027) | Independent auditor | — |
The first three rows are our own assessment, not a certification. No body certifies GDPR, CCPA or UK DPA compliance, so nobody can issue a certificate for them and anyone showing you one is selling something. We list them because the machinery behind them is real and you can exercise it yourself: erasure under Article 17 and data export under Article 20 both run from your privacy controls. The rows assessed by an independent auditor are the ones that will carry outside attestation, and none of them is finished.
Sub-processors
We work with these vendors to operate RoadSeal. Each has signed a DPA aligned with our privacy policy. Last updated April 2026.
| Vendor | Purpose | Data residency |
|---|---|---|
| Stripe | Payment processing & identity verification | USA / Ireland |
| Supabase (PostgreSQL) | Application database + auth | EU (Frankfurt) |
| Cloudflare Pages | Static hosting + CDN | Global edge |
| Resend | Transactional email delivery | USA |
| Anthropic (Claude API) | AI chat assistant — when enabled by user | USA |
| Trustpilot | Review collection — opt-in | EU (Denmark) |
| Google (GA4 + Maps) | Analytics + address lookup — consent-gated | USA + Global |
Security roadmap
We're an early-stage company building toward formal certification. Below is an honest picture of where we are and what's planned — we don't claim audits we haven't completed.
SOC 2 Type II
Independent attestation of security controls over time, once the Type I milestone is complete.
SOC 2 Type I
First independent attestation of our security posture at a point in time.
Row-Level Security across the database
Every application table enforces row-level isolation between customers and staff, with privileged actions written to an append-only audit log.
Payments handled by Stripe
Card data is processed by Stripe (PCI-DSS Level 1); we never store card numbers. How long we keep the documents you upload is set out in our Privacy Policy.
Reporting concerns
Security vulnerability
Email [email protected] with details; the machine-readable contact is in /security.txt and the rules of engagement are in our security policy. We aim to acknowledge good-faith reports within three business days.
Privacy / GDPR request
Email [email protected] or use the self-service portal for data export and deletion. 30-day SLA.
Compliance / press
Email [email protected] for legal inquiries, audit cooperation, or press requests for compliance details.
Live status
Real-time uptime, incidents, and maintenance windows on status.roadseal.co.