Trust Center

Updated July 2026

Permit work involves site plans, contracts, and personal details. This page explains exactly how PermitJunkie protects that data, who else can touch it, how long we keep it, and what happens if something goes wrong. Everything here reflects controls that are implemented today — not roadmap.

Security posture

Encryption everywhere

TLS 1.2+ in transit with HSTS on published domains. AES-256 at rest for the database and object storage.

Least-privilege access

Row-Level Security on every table in the application schema, scoped to your account or workspace membership. Admin routes are verified server-side — never with a client-side flag.

Data minimization

We collect name, email, phone, project address, and permit content. We never collect SSNs, government IDs, or card numbers — payment cards are held entirely by Stripe.

Audited admin actions

Every privileged action writes an immutable audit record. Security drift, incidents, and QA runs are monitored continuously and mapped to control evidence.

Compliance status

We run a continuous SOC 2 control program internally: controls are tested on a schedule, evidence is collected automatically from our audit systems, and access reviews run quarterly. We are not yet SOC 2 Type II certified — an independent audit is planned, and we will not claim a certification we do not hold.

Our infrastructure providers (Supabase, Cloudflare, Stripe) are independently SOC 2 Type II attested. For procurement reviews we can provide our security policy, subprocessor list, retention policy, incident-response runbook, access-review procedure, and a current control-evidence summary under NDA.

Subprocessors

Third-party services that process PermitJunkie customer data
VendorPurposeData exposedRegionAttestation
Supabase (via Lovable Cloud)Database, auth, object storageCustomer data at rest, encryptedUSSOC 2 Type II · GDPR DPA
LovableHosting, deploys, secrets vault, AI gatewayDeploy artifacts, encrypted secrets, gateway payloadsUSSOC 2 in progress · DPA
CloudflareCDN, DDoS protection, edge runtimeRequest headers, IPs, TLS terminationGlobal edgeSOC 2 Type II · GDPR DPA
StripePayments, subscriptions, invoicingName, email, billing address, amountsUSPCI DSS Level 1 · SOC 1 & 2
ResendTransactional emailRecipient address and message contentUSDPA
DocuSign / PandaDocE-signature (opt-in only)Documents you send for signatureUSSOC 2 Type II
BlueNotary / OneNotary / ProofRemote online notarization (opt-in only)Documents and signer identity verificationUSVendor-held ID data

New subprocessors go through security review before they touch customer data. Notarization and e-signature vendors only receive data if you explicitly connect them.

Data handling

Retention & deletion

You can export or delete your data at any time from Account Settings, or by emailing privacy@permitjunkie.com.

Verified deletion requests are fulfilled within 30 days (typically 7). Billing records are retained for 7 years for tax law, and audit entries are retained for 2 years with personal identifiers removed.

Incident response

Suspected incidents are declared within 1 hour of detection, with the CTO as incident commander.

Customers affected by a confirmed breach are notified within 72 hours, and a written post-mortem is filed within 7 days.

How we use AI

AI is used to read permit documents, draft packets, and explain jurisdiction requirements. Every AI recommendation shows its reasoning, evidence, and confidence.

AI output is never presented as the work or approval of a licensed professional. Work requiring an architect, engineer, or attorney is routed to a human, and AI-generated content is labeled as such.

Government & jurisdiction data

Jurisdiction requirements are sourced from official municipal, county, and state publications, with each source tracked and re-verified on a cadence.

See the Government Trust page for scoring methodology and source transparency.

What we don't do

  • No third-party ad networks.
  • No session-replay vendors.
  • No marketing analytics that receive your permit data.
  • No offshore data processors.
  • Your permit content is never used to train third-party models.

Security contact

Report a vulnerability or request the procurement security package at security@permitjunkie.com. We acknowledge reports within one business day and never pursue good-faith researchers.

Contact us