Trust Center
Permit work involves site plans, contracts, and personal details. This page explains exactly how PermitJunkie protects that data, who else can touch it, how long we keep it, and what happens if something goes wrong. Everything here reflects controls that are implemented today — not roadmap.
Security posture
TLS 1.2+ in transit with HSTS on published domains. AES-256 at rest for the database and object storage.
Row-Level Security on every table in the application schema, scoped to your account or workspace membership. Admin routes are verified server-side — never with a client-side flag.
We collect name, email, phone, project address, and permit content. We never collect SSNs, government IDs, or card numbers — payment cards are held entirely by Stripe.
Every privileged action writes an immutable audit record. Security drift, incidents, and QA runs are monitored continuously and mapped to control evidence.
Compliance status
We run a continuous SOC 2 control program internally: controls are tested on a schedule, evidence is collected automatically from our audit systems, and access reviews run quarterly. We are not yet SOC 2 Type II certified — an independent audit is planned, and we will not claim a certification we do not hold.
Our infrastructure providers (Supabase, Cloudflare, Stripe) are independently SOC 2 Type II attested. For procurement reviews we can provide our security policy, subprocessor list, retention policy, incident-response runbook, access-review procedure, and a current control-evidence summary under NDA.
Subprocessors
| Vendor | Purpose | Data exposed | Region | Attestation |
|---|---|---|---|---|
| Supabase (via Lovable Cloud) | Database, auth, object storage | Customer data at rest, encrypted | US | SOC 2 Type II · GDPR DPA |
| Lovable | Hosting, deploys, secrets vault, AI gateway | Deploy artifacts, encrypted secrets, gateway payloads | US | SOC 2 in progress · DPA |
| Cloudflare | CDN, DDoS protection, edge runtime | Request headers, IPs, TLS termination | Global edge | SOC 2 Type II · GDPR DPA |
| Stripe | Payments, subscriptions, invoicing | Name, email, billing address, amounts | US | PCI DSS Level 1 · SOC 1 & 2 |
| Resend | Transactional email | Recipient address and message content | US | DPA |
| DocuSign / PandaDoc | E-signature (opt-in only) | Documents you send for signature | US | SOC 2 Type II |
| BlueNotary / OneNotary / Proof | Remote online notarization (opt-in only) | Documents and signer identity verification | US | Vendor-held ID data |
New subprocessors go through security review before they touch customer data. Notarization and e-signature vendors only receive data if you explicitly connect them.
Data handling
You can export or delete your data at any time from Account Settings, or by emailing privacy@permitjunkie.com.
Verified deletion requests are fulfilled within 30 days (typically 7). Billing records are retained for 7 years for tax law, and audit entries are retained for 2 years with personal identifiers removed.
Suspected incidents are declared within 1 hour of detection, with the CTO as incident commander.
Customers affected by a confirmed breach are notified within 72 hours, and a written post-mortem is filed within 7 days.
AI is used to read permit documents, draft packets, and explain jurisdiction requirements. Every AI recommendation shows its reasoning, evidence, and confidence.
AI output is never presented as the work or approval of a licensed professional. Work requiring an architect, engineer, or attorney is routed to a human, and AI-generated content is labeled as such.
Jurisdiction requirements are sourced from official municipal, county, and state publications, with each source tracked and re-verified on a cadence.
See the Government Trust page for scoring methodology and source transparency.
What we don't do
- No third-party ad networks.
- No session-replay vendors.
- No marketing analytics that receive your permit data.
- No offshore data processors.
- Your permit content is never used to train third-party models.
Security contact
Report a vulnerability or request the procurement security package at security@permitjunkie.com. We acknowledge reports within one business day and never pursue good-faith researchers.