Trust & Security
How SupplyLoop protects your data
SupplyLoop handles project estimates, margins, and vendor pricing for contractors and suppliers. This page describes how that data is handled, hosted, and protected. We're an early-stage product and keep this page honest about what we do today.
Hosting & infrastructure
SupplyLoop's application runs on Vercel. Your data is stored in a managed PostgreSQL database (Supabase), hosted on Amazon Web Services. Both are established cloud platforms that maintain their own physical, network, and operational security controls.
Data residency
Your data is currently hosted in the AWS Asia Pacific (Mumbai) region. SupplyLoop is UAE-focused, and we're evaluating a Middle-East region for customers with in-region data-residency requirements. If residency matters for your procurement, email support@supplyloop.aiand we'll discuss options.
Encryption
All traffic between your browser and SupplyLoop is encrypted in transit over HTTPS/TLS, and HSTS is enabled so connections can't quietly fall back to unencrypted HTTP. Your data is encrypted at rest by our infrastructure providers (AWS / Supabase).
Access & authentication
Using SupplyLoop requires a signed-in account, obtained by invitation or by purchasing a membership. Passwords are hashed with scrypt — never stored in plain text — sessions use signed, http-only cookies, sign-in and sign-up are rate-limited, and email addresses are verified. Optional sign-in with Google is available. Every request for your commercial data — projects, BOQs, rates, margins, and vendor pricing — is authorization-checked in the application against your signed-in account, so one company's data stays scoped to that company and is not returned to another.
Sub-processors
We rely on a small set of trusted service providers to run SupplyLoop. The current list:
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting & delivery | Global edge |
| Supabase (on AWS) | Primary database (PostgreSQL) | Mumbai (ap-south-1) |
| Stripe | Payment processing | Global |
| OpenAI | AI features (Sidekick, takeoff, BOQ extraction) | United States |
| Resend | Transactional email | Global |
| Optional sign-in (OAuth) | Global |
This list can change as we grow; email support@supplyloop.ai for the current, complete list.
AI & your data
Some features — Sidekick, drawing takeoff, and BOQ extraction — use AI (OpenAI) to produce a result. The content you submit to those features (for example a drawing or a bill of quantities) is sent to that provider to generate the output. We may use aggregated and de-identified data to improve our own estimation and materials-matching models. We do not sell your data. How your data is used is set out in our Privacy Policy, and enterprise customers can request a Data Processing Agreement (DPA).
Data retention & deletion
We keep your account data for as long as your account is active, so your projects, estimates, and order history stay available to you. You can request an export or deletion of your data at any time by emailing support@supplyloop.ai, and we'll action it.
Incident response
If we become aware of a security incident affecting your data, we investigate promptly and notify affected customers without undue delay, with the information you need to respond.
Reporting a vulnerability
Found a security issue? Please report it responsibly to support@supplyloop.ai. We won't pursue legal action against good-faith researchers who follow responsible disclosure and don't access, modify, or delete other users' data. Our security.txt has machine-readable contact details.
Compliance & certifications
SupplyLoop is an early-stage product. We are not yet SOC 2 or ISO 27001 certified, but our practices are built to align with those frameworks and we'll pursue formal certification as we grow. For a security questionnaire, a DPA, or a due-diligence review, email support@supplyloop.ai.
Questions
For security questions, due-diligence requests, or to report a concern, email support@supplyloop.ai.
