Trust and security
How we handle your data.
Surface processes payments through Stripe and never stores card data. Client data lives in Supabase. Access follows least privilege. SOC 2 is on the roadmap, not yet certified.
The short version
Card data
Held by Stripe, a PCI-DSS Level 1 provider. Surface never sees your full number.
Client data
Stored in Supabase (PostgreSQL). Never sold, never used to train public models.
Access
Least privilege by default. Privileged keys stay server-side, never in the browser.
Payments via Stripe
Surface is $149 a month (USD) with 200 credits. Its 3-day trial requires a card and includes 40 credits. Billing runs through Stripe. Card details are entered into and held by Stripe, a PCI-DSS Level 1 provider.
Surface never sees or stores your full card number. We store only the non-sensitive billing references Stripe returns (such as a customer ID and the last four digits) needed to manage your subscription.
Does Surface store my card details?
No. Your card is entered into and held by Stripe, a PCI-DSS Level 1 provider. Surface stores only a customer ID and the last four digits, never the full number.
- Processor
- Stripe
- Plan
- $149/mo, 200 credits, 3-day card trial, 40 trial credits
- Card number stored
- Never
Posture in three numbers
Cards live with Stripe. Surface keeps only a customer ID and the last four digits.
A short, public list. Each one receives only the data it needs for its stated purpose.
The Supabase service-role key never reaches the browser, client code, or source control.
Data we store, and where
We store the data you give us during onboarding and the data we enrich from your business email domain: company profile, website, the audit inputs you submit, and the AI-visibility results we generate for you.
This data is held in our primary database hosted on Supabase (PostgreSQL). Operational communication happens in-product and by email through Resend. We do not sell your data, and we do not use it to train public models.
Sub-processors
We rely on a short list of third parties to deliver the service. Each receives only the data it needs for its stated purpose.
| Sub-processor | Purpose |
|---|---|
| Apollo.io | Company data enrichment from a business email domain. |
| Enrich.so | Professional contact enrichment (name, role, LinkedIn). |
| Anthropic | AI analysis and content generation (Claude models). |
| DataForSEO | On-demand AI-search and SERP data for audits and reporting. |
| Supabase | Primary database hosting (PostgreSQL) for account and project data. |
| Stripe | Recurring billing. Card data is held by Stripe, never by Surface. |
| Vercel | Web hosting and content delivery for this site. |
| Resend | Email delivery for reports and operational messages. |
Access control and least privilege
Access to client data follows the principle of least privilege: each component holds only the permissions it strictly requires.
Privileged database credentials (the Supabase service-role key) are server-only. They are never shipped to the browser, never exposed in client code, and never committed to source control.
SOC 2
We are building toward SOC 2 and following its control practices today. We are not SOC 2 certified yet, and we will not display a badge we have not earned.
When the audit completes, we will state the report type and date here.
Status
Planned, not yet certified
Our llms.txt
We practice what we sell. Surface publishes its own llms.txt so AI engines can read a clean, canonical index of this site.
Security contact
Found a vulnerability or have a security question? Email us and we will respond.
Email:security@surfacehq.co

