๐Ÿ”’ Trust Center

Security, privacy, and transparency.

PARIE is built on Google Firebase with server-enforced tenant isolation, AES-256 encryption, and a documented incident response process. We'd rather tell you what we haven't done yet than hide it โ€” scroll all the way down for the honest gap list.

At a glance

Where we stand โ€” April 2026

Uptime target
99.9% / month
Firebase 99.95% inherited
RPO / RTO
24 h / 4 h
Daily Firestore backups
SOC 2 Type I
In readiness
Target audit Q4 2026
GDPR / CCPA
Compliant
DPA available ยท EU region on request
Encryption
AES-256
App-layer + at-rest
TLS
1.2+ enforced
HSTS ยท auto-rotated certs
SSO / SAML
Q3 2026
Enterprise tier
Pen test
Q3 2026
Annual cadence thereafter
Architecture

How PARIE protects your data

Authentication and identity

Firebase Auth handles all authentication โ€” passwords never touch PARIE servers. 6 roles (user, manager, HR admin, company admin, client admin, super admin) enforced server-side via Firestore security rules.

Email / password Google OIDC MFA available SAML 2.0 โ€” Q3 2026

Multi-tenant isolation

Each tenant lives under clients/{tenantId}. Every read/write path has an isMemberOf(tenantId) rule. Cross-tenant data access is impossible through supported paths. Verified by static review + automated tests.

Tenant-scoped rules Per-tenant encryption keys Regression test suite

Encryption

TLS 1.2+ everywhere. AES-256-GCM at the application layer for uploaded documents. AES-256 at-rest via Google Cloud KMS. Keys rotated annually or on compromise.

TLS 1.2+ AES-256-GCM BYOK / CMK โ€” Q1 2027

AI safety

All LLM calls pass through a server-side proxy (claudeProxy) that enforces authentication, tenant resolution, tier gating, monthly caps, and rate limits. The Anthropic API key never touches the browser.

Server-side key Tier enforcement Per-user rate limit No prompt retention (Anthropic terms)

Backup and recovery

Daily Firestore export to a separate Google Cloud Storage bucket; 90-day retention; weekly verified restore; annual DR exercise. RPO 24 h, RTO 4 h.

Daily backup Weekly restore test PITR โ€” Q4 2026

Incident response

Documented runbook with severity matrix. Customer notification within 72 hours of confirmed incident (more aggressive for Sev 1). Post-incident RCA shared with affected customers within 10 business days.

72 h SLA Written RCA GDPR Art. 33 aligned
Compliance

Frameworks and attestations

FrameworkStatusNotes
GDPRCompliantDPA available; SCCs incorporated; EU-region hosting available on request.
CCPA / CPRACompliantPrivacy policy covers California consumer rights; deletion on request within 30 days.
SOC 2 Type IIn readinessTarget audit Q4 2026. Weekly status available to Enterprise prospects on request.
SOC 2 Type IIPlannedQ2 2027 (6-month observation window after Type I).
HIPAABAA-readySeparate BAA executable after scoped HIPAA controls complete (see Trust docs).
ISO 27001InheritedGoogle Cloud infrastructure layer. No PARIE-level certification planned.
PCI DSSN/APARIE does not store or process cardholder data. Stripe handles all payments.
Subprocessors

Who else touches your data

SubprocessorPurposeDataLocation
Google Cloud / FirebaseHosting, database, auth, serverless computeAll customer data (encrypted)US (default) ยท EU / UK / APAC on request
Anthropic PBCLLM inference (Claude API)Prompts + context per call (no retention)US
StripePayment processingBilling metadata only; no card dataUS
PostmarkTransactional emailEmail addresses + contentUS
NamecheapDomain and DNSPublic DNS onlyUS

Full list and change history: parie.io/subprocessors. New subprocessors announced 30 days in advance.

Transparency

What we have NOT yet done

We list the gaps so you can decide if they're blockers for you. If any of these is a dealbreaker, talk to us early and we'll scope remediation in the Order Form.

SOC 2 Type II

Targeted Q2 2027. Type I readiness is in progress now. We'll share audit observation access on customer request.

Independent penetration test

Scheduled Q3 2026, annual thereafter. Report available under NDA.

24/7 on-call rotation

Founder-led response today; named rotation launches with the first SLA-bound Enterprise customer.

Dedicated CISO

Security responsibilities are founder-held. Formal role when we cross 5 engineers or a customer requires it.

Customer-managed keys

BYOK / CMK support planned Q1 2027 for Enterprise+.

Formal ISMS documentation

Lightweight today. Full ISO-style policy set is being built alongside SOC 2 engagement.

Security questions? Ask anything.

We answer enterprise security questionnaires (SIG Lite, CAIQ v4, HECVAT) from scratch within 3 business days. Legal, privacy, and DPA questions within 2 business days.

hello@parie.io