Security — the boring page that matters.

You're trusting us with client information. Here is exactly where it lives, how it's protected, and — just as important — what we never ask for.

What we never ask for

Where your data lives

All practice and client records are stored in a dedicated database in Sydney, Australia (Supabase, on AWS ap-southeast-2), encrypted in transit (TLS) and at rest. Two narrow exceptions, stated plainly: transactional email (such as sign-in links) is delivered via Resend, whose infrastructure processes email data in the United States, and payments are processed by Stripe, which operates globally. Client authority data itself stays in the Sydney database.

Practice isolation

Every table enforces row-level security: your practice's data is invisible to every other practice at the database layer, not just the application layer. There are no shared workspaces and no cross-practice queries.

Payments

Billing runs entirely through Stripe. Your card number never touches our servers and we cannot see it.

The Fund Response Index

The index (in development — first edition publishes once founding-cohort request volume permits) will use aggregated response-time data only — fund names and day counts. No client information, practice names, or request contents are ever included.

Deletion

Ask and it's gone: contact us to delete your practice and all client data permanently. Cancelling your subscription does not silently delete data (so you can come back), but a deletion request removes everything.

Honest limits

SuperChase is a young product from a small independent team. We hold no SOC 2 or ISO 27001 certification yet — we'd rather tell you that plainly than imply otherwise. The architecture above is real, verifiable, and built conservative-first.