Trust and security

How we handle your data.

Surface processes payments through Stripe and never stores card data. Client data lives in Supabase. Access follows least privilege. SOC 2 is on the roadmap, not yet certified.

Surface security posture / Last updated: 2026-06-06

The short version

Card data

Held by Stripe, a PCI-DSS Level 1 provider. Surface never sees your full number.

Client data

Stored in Supabase (PostgreSQL). Never sold, never used to train public models.

Access

Least privilege by default. Privileged keys stay server-side, never in the browser.

Trust and security

Payments via Stripe

Surface is $149 a month (USD) with 200 credits. Its 3-day trial requires a card and includes 40 credits. Billing runs through Stripe. Card details are entered into and held by Stripe, a PCI-DSS Level 1 provider.

Surface never sees or stores your full card number. We store only the non-sensitive billing references Stripe returns (such as a customer ID and the last four digits) needed to manage your subscription.

Trust and security

Does Surface store my card details?

No. Your card is entered into and held by Stripe, a PCI-DSS Level 1 provider. Surface stores only a customer ID and the last four digits, never the full number.

Processor
Stripe
Plan
$149/mo, 200 credits, 3-day card trial, 40 trial credits
Card number stored
Never

Posture in three numbers

0Card numbers stored
8Named sub-processors
100%Privileged keys server-side

Cards live with Stripe. Surface keeps only a customer ID and the last four digits.

A short, public list. Each one receives only the data it needs for its stated purpose.

The Supabase service-role key never reaches the browser, client code, or source control.

01 /Trust and security

Data we store, and where

We store the data you give us during onboarding and the data we enrich from your business email domain: company profile, website, the audit inputs you submit, and the AI-visibility results we generate for you.

This data is held in our primary database hosted on Supabase (PostgreSQL). Operational communication happens in-product and by email through Resend. We do not sell your data, and we do not use it to train public models.

03 /Trust and security

Sub-processors

We rely on a short list of third parties to deliver the service. Each receives only the data it needs for its stated purpose.

Sub-processorPurpose
Apollo.ioCompany data enrichment from a business email domain.
Enrich.soProfessional contact enrichment (name, role, LinkedIn).
AnthropicAI analysis and content generation (Claude models).
DataForSEOOn-demand AI-search and SERP data for audits and reporting.
SupabasePrimary database hosting (PostgreSQL) for account and project data.
StripeRecurring billing. Card data is held by Stripe, never by Surface.
VercelWeb hosting and content delivery for this site.
ResendEmail delivery for reports and operational messages.
04 /Trust and security

Access control and least privilege

Access to client data follows the principle of least privilege: each component holds only the permissions it strictly requires.

Privileged database credentials (the Supabase service-role key) are server-only. They are never shipped to the browser, never exposed in client code, and never committed to source control.

05 /Trust and security

SOC 2

We are building toward SOC 2 and following its control practices today. We are not SOC 2 certified yet, and we will not display a badge we have not earned.

When the audit completes, we will state the report type and date here.

Status

Planned, not yet certified

06 /Trust and security

Our llms.txt

We practice what we sell. Surface publishes its own llms.txt so AI engines can read a clean, canonical index of this site.

07 /Trust and security

Security contact

Found a vulnerability or have a security question? Email us and we will respond.

Email:security@surfacehq.co

Work with Surface

Get cited in AI answers, on a stack you can trust.