Privacy Policy
Last updated: July 22, 2026
Proofsteady is operated from Thrive Business Center, 105, 11500 29 Street SE, Calgary, AB, Canada T2Z 3W9. This policy explains what we collect, why, and the choices you have. The short version: we collect what the service needs to run, we encrypt what's sensitive, we don't sell data, and we don't use your data to train AI models.
What we collect
We collect four kinds of information:
- Account information: your name, email address, and workspace details, handled through our authentication provider (Clerk).
- Integration credentials: the read-only keys and tokens you provide to connect your systems. These are encrypted at rest (AES-256-GCM, scoped to your organization) and are never displayed back in the UI.
- Compliance data: configuration and security-posture metadata read from the systems you connect, check results, and the evidence artifacts the platform collects. Where you use roster features, this can include the names and work emails of your team members.
- Usage and log data: standard service logs and audit trails of actions taken in your workspace.
How we use it
We use this information to run the service: testing controls, collecting evidence, opening remediation issues, sending the notifications you configure, providing support, and keeping the platform secure. We do not sell personal information, we do not use your data for advertising, and we do not use your data to train AI models.
Subprocessors
We rely on a small set of infrastructure providers to deliver the service:
- DigitalOcean (application hosting)
- Supabase (database and evidence storage)
- Clerk (authentication)
- Cloudflare (DNS, TLS, and traffic protection)
Security
Connector credentials are encrypted at rest with AES-256-GCM using organization-bound keys. Traffic is encrypted in transit. Connectors use least-privilege, read-only access. Privileged actions are recorded in a tamper-evident audit log, and evidence lives in private storage accessed through short-lived signed URLs.
Retention and deletion
Account and workspace data is kept for the life of the account. Evidence and check history follow the retention configured for your workspace. Deleting a workspace removes its data across the platform. You can request deletion of your personal information at any time using the contact below.
Your rights
You can request access to, correction of, export of, or deletion of your personal information. We honor rights under PIPEDA (Canada) and, where applicable, the GDPR and UK GDPR. We respond to verified requests within 30 days.
Where data is processed
Our infrastructure runs with the subprocessors listed above, and data may be processed in the United States and Canada.
Cookies
The site and app use essential cookies only: your sign-in session and Cloudflare's security cookie. We do not use advertising trackers.
Changes and contact
If this policy changes materially, we'll update the date above and note the change here. Questions or requests: [email protected], or write to Proofsteady at the address above.