Trust Center
Security & compliance at Supercenter
Supercenter is the control plane for enterprise AI agents — skills, integrations and AI coworkers that act inside your existing tools. Security is structural, not bolted on: agents get scoped, encrypted credentials resolved only at execution time; consequential actions require human approval; every tool call is audit-logged with on-behalf-of attribution; and cross-user access exists only through explicit, revocable delegation grants.
This page is generated live from our internal compliance system — the same controls, monitors and vendor register our team operates on. Request access below for the gated document set (DPA, policies, reports).
FAQ
Certifications, encryption, isolation, backups, recovery, exit strategy and company continuity.
Certifications & frameworks
Do you hold ISO 27001, SOC 2, TISAX, C5 or ISAE 3402 certifications?
Not yet. A SOC 2 program (Security, Availability, Confidentiality) is underway, targeting a Type I report followed by a Type II observation window. GDPR compliance is documented; we are established in Austria (EU). A DORA ICT third-party readiness package is available for financial-entity customers. ISO 27001 will be evaluated based on customer demand. TISAX and C5 are not planned. The policy stack and control register are available under NDA via the document request below.
Can our security team send you a questionnaire or audit you?
Yes. We answer security questionnaires (VSA, CAIQ, SIG-lite or your own template) from a maintained answer bank, typically within two business days. Audit and information rights are defined in our DPA and are satisfied through documentation and reports, with deeper reviews available under enterprise agreements.
Encryption & key management
How is data encrypted in transit and at rest?
All traffic uses TLS 1.2 or higher with HSTS. Data is encrypted at rest by our infrastructure providers (Vercel, Convex). Connector credentials, OAuth tokens and channel secrets are additionally encrypted at the application layer with AES-256-GCM, so a database-level compromise alone cannot expose integration credentials.
How are encryption keys managed?
The credential encryption key is a dedicated secret, separate from authentication and provider secrets, held in platform environment configuration and never in the repository (CI secret scanning enforces this). Rotation follows a documented runbook with an envelope re-encryption procedure. Automated monitors verify continuously that every stored credential is encrypted, and their status feeds the controls on this page.
Tenant isolation & access control
How are customer workspaces isolated from each other?
Every record is scoped to an organization, and every backend function authenticates its caller and enforces that scope. A CI check fails the build if any backend function lacks an authorization gate. Agents run in isolated per-session sandboxes. Credentials are resolved server-side at execution time and never enter prompts or model context. Cross-user access requires an explicit, revocable delegation grant, and every delegated call is attributed in the audit log.
Who at Supercenter can access customer data?
Access follows least privilege: a small, monitored superadmin allowlist; SSO-backed accounts with MFA; and support access only through audited, time-boxed impersonation that is visible in the audit log. Production data is accessed only for operational need, as defined in the Access Control and Employee Security policies.
AI-specific safeguards
Is our data used to train AI models?
No. Inference runs through the Vercel AI Gateway with zero data retention at the gateway. The model providers (Anthropic, OpenAI, Google, xAI) operate under no-training commercial terms as the gateway's sub-processors. We do not train models on customer data.
What stops an AI agent from doing something destructive?
Consequential actions require human approval before execution. Agents act with scoped credentials resolved per call, never ambient access. Every tool call is audit-logged with on-behalf-of attribution. Agent sessions run in isolated sandboxes. Prompt injection from connected content is mitigated through these approval gates and credential scoping.
Backups & disaster recovery
What is your backup strategy: frequency, retention, geography, restore testing?
The primary database (Convex) is continuously backed up on managed multi-AZ infrastructure in the United States, with scheduled independent exports. The business continuity plan commits to a 24-hour RTO and a 24-hour RPO for catastrophic provider events, with a documented restore runbook and an annual restore test. Retention follows the published schedule: session transcripts 180 days, audit logs 400 days, usage events 90 days.
Can we export or back up our data ourselves?
Yes. Workspace data can be exported on request in standard formats (JSON, CSV, Markdown), and personal data exports run through our data subject request tooling. Most customer data also remains in the customer's own systems of record (email, chat, documents, CRM); Supercenter connects to those tools rather than replacing them.
Data export & exit strategy
How hard is it to leave Supercenter?
Disconnecting an integration revokes our access immediately. Your systems of record (email, chat, documents, CRM) are unaffected by leaving. On termination we export requested data in standard formats and delete or anonymize all customer data within 30 days, with confirmation available on request, per the DPA and retention policy.
Subprocessors & international transfers
Where is data processed, and under what transfer safeguards?
Production data is processed in the United States on managed infrastructure (Vercel, Convex), encrypted in transit and at rest. Transfers from the EEA, UK and Switzerland are covered by the EU Standard Contractual Clauses incorporated in our DPA, supported by transfer impact assessments and supplementary measures.
How do you manage subprocessor changes?
The subprocessor list on this page is generated from our vendor register. We give at least 30 days notice of new or replaced subprocessors, with objection rights per the DPA. Each subprocessor is bound by data protection terms no less protective than ours.
Incident response & breach notification
What happens if you have a security incident?
We operate an approved incident response plan: triage and containment, customer notification without undue delay per the DPA, supervisory authority notification within 72 hours where GDPR requires it, and a postmortem with tracked corrective actions. Service status is published on the status page.
Company & operational continuity
You're a young company. What happens if Supercenter disappears?
Your systems of record stay yours: Supercenter connects to tools you already run, so your data does not leave with us. The platform runs on managed multi-AZ infrastructure with no self-operated servers. The DPA commits to data export and deletion or return on termination, and the continuity plan covers key-person unavailability through shared credential recovery. Supercenter is operated from Vienna, Austria (VAT ATU82884407) by a founder with three previously shipped products (Mokker, Zerolens, Yourmap).
What support and uptime commitments do you make?
Live status and incident history are public on the status page. Security reports are acknowledged within two business days. SLA and support terms are agreed per enterprise contract.
Vulnerability disclosure & secure development
How do we report a vulnerability?
Email security@supercenter.app, also published in /.well-known/security.txt. Reports are acknowledged within two business days, and we do not pursue good-faith research. Every change runs through CI with secret scanning and authorization-gate checks. Dependencies follow a 14-day cooldown policy with expedited handling for known CVEs. An external penetration test is scheduled as part of the SOC 2 program.
Security contact
Vulnerability reports and security questions: security@supercenter.app. Reports are acknowledged within two business days. We do not pursue good-faith research.