Security
This page states only what is true today. We say plainly what we do not have yet, further down.
Where ReedPort runs
- The app runs on North Trestle-operated servers, behind Cloudflare.
- The marketing site (reedport.com) runs on Cloudflare Workers.
- The database is Neon, a serverless Postgres provider, in AWS US East 1 (Northern Virginia), United States.
In transit
Every connection uses TLS: browser to Cloudflare, Cloudflare to our servers, and our servers to the database.
At rest
Neon encrypts stored data with AES-256.
Backups
Your shop's records live in a hosted database with point-in-time restore covering the last 6 hours on our current database plan.
Who can see what
One database holds every shop, and every row is scoped to your shop. Inside your shop, your staff see what their role allows; shop-wide labor and parts totals open only behind your Profit PIN. Our own team opens a shop's records only to help with a problem you asked us about, or when the law requires it.
Reading a receiving document
When you drop a vendor packing slip or invoice on the Receive page, we send that document to Anthropic, which reads it and returns the part lines. Under Anthropic's commercial terms it does not train models on that content. Nothing else in your shop's records is sent there. Typing the lines in by hand keeps the document on our systems.
Payments
Your subscription payment to us runs through Stripe Checkout. If you turn on card payments in Settings, your shop's own customer card payments run through Stripe Connect, by payment link, Stripe reader, or tap to pay. In every case, card numbers go to Stripe and never touch ReedPort's servers, which is why our integration qualifies for PCI SAQ A. Stripe itself is a PCI DSS Level 1 service provider.
Transactional email (verify links, receipts, invites) is sent from an authenticated domain.
Our vendors' attestations
These are our vendors' certifications, not ours:
- Neon: SOC 2 Type 2 and ISO 27001 / 27701, reported on their trust center.
- Stripe: PCI DSS Level 1 service provider.
- Cloudflare: see Cloudflare's own trust and compliance hub.
See our subprocessors page for the full vendor list and their DPAs.
What we do not have yet
- No third-party security audit of ReedPort itself.
- No formal uptime SLA.
- No separate audit trail of our own access to a shop's records. Server logs record the request; there is no report you can pull.
We are not SOC 2, HIPAA, or GDPR certified, and we do not claim to be. The vendors above hold their own attestations, cited above as theirs.
Reporting a problem
Email security@reedport.com. We acknowledge reports within one business day, and we notify affected shops without undue delay if an incident affects their data.
Data Processing Addendum
Available on request. Email privacy@reedport.com. Most United States shops do not need one; ask if your insurer or your own customers require it.