SureSteps Trust CenterDeep Dive

Private distribution. This document is intended for customer security and procurement review under applicable confidentiality terms.

Subprocessors

SureSteps maintains a subprocessors register and provides at least 14 days' written notice (email to the customer's designated contact) before engaging a new subprocessor that will process customer data. This list reflects core production services used for application delivery, AI features, logging, monitoring, and customer communication.

VendorCategoryPurposeData Handling SummarySOC 2 / ISO StatusDPA
AWSInfrastructurePrimary cloud hostingCompute, storage, networking, logs, and backupsSOC 2 Type II, ISO 27001 (published)Y — AWS's standard DPA covers all AWS services in use
AnthropicAI ModelLLM inferencePrompt/response processing with provider retention controlsSOC 2 Type II (published)Y — retains API inputs/outputs for up to 7 days, solely for abuse prevention/safety monitoring; not used for training
BraintrustAI ObservabilityLLM evaluation and tracingEvaluation traces and quality telemetrySOC 2 Type II, currently valid (report available under NDA); ISO 27001 not publishedY — executable on request. Separately retains full prompt/response traces for up to 14 days, for logging/abuse-prevention/safety purposes only, not training
n8nWorkflowAutomation orchestrationTask payloads and workflow metadataSOC 2 Type II (full report for enterprise customers, SOC 3 summary otherwise); ISO 27001 not publishedY — published at n8n.io/legal/data-processing-agreement
NangoIntegrationsOAuth and connector syncConnection tokens and integration metadataSOC 2 Type II; ISO 27001 not publishedY — auto-applies to cloud accounts
Auth0IdentityAuthentication and user sessionsUser identity attributes and auth logsSOC 2 Type II (published)Y — Auth0's standard DPA
SendGridCommunicationsTransactional email deliveryRecipient email and message metadataSOC 2 Type II (published)Y — Twilio/SendGrid's standard DPA
PostHogProduct AnalyticsUsage analyticsEvent-level product interaction telemetrySOC 2 Type II (published report); ISO 27001 not publishedY — published in their Trust Center
QdrantVector DatabaseRetrieval and semantic searchEmbeddings and scoped vector recordsSOC 2 Type II confirmed; ISO 27001 status not corroborated on Qdrant's own pages despite third-party claimsY — published at cloud.qdrant.io/dpa
Fly.ioEdge RuntimeService deployment footprintService runtime and network metadataSOC 2 Type II; underlying datacenters are ISO 27001-certified facilities, not an org-level Fly.io certificationY — pre-signed, activates on customer signature
CloudflareNetwork SecurityWAF/CDN and traffic controlsRequest metadata and edge filtering dataSOC 2 Type II, ISO 27001 (published)Y — Cloudflare's standard DPA
SentryMonitoringError trackingError payloads, stack traces, issue metadataSOC 2 Type II (published)Y — Sentry's standard DPA
Dash0ObservabilityOperational telemetryMetrics, logs, and tracesSOC 2 Type II; ISO 27001 in progress, not yet certifiedY — published at dash0.com/policies/dpa
LiveKitRealtime MediaAudio/video transportRealtime stream metadata and session controlsSOC 2 Type II; ISO 27001 in progress, not yet certified (also pursuing PCI DSS)Y — available; LiveKit maintains its own public subprocessor list
AssemblyAISpeech AITranscriptionAudio snippets and transcription outputsSOC 2 Type II (all Trust Service Criteria); ISO 27001 certifiedY — published, auto-incorporated into their ToS
Voyage AIEmbeddingsEmbedding generationText segments transformed to embeddingsNot confirmed for the standalone product following the 2025 MongoDB acquisition — parent MongoDB holds SOC 2, but extension to Voyage AI specifically isn't publicly documentedY — published at voyageai.com/dpa
CohereAI ModelSupplementary model servicesPrompt/response processing under provider termsSOC 2 Type II (audited annually); ISO 27001 and ISO 42001 certifiedY — available on request via direct contact, not a self-serve download

Secrets & API Key Management

Secrets and variables are managed in GitHub Actions, scoped by dev and prod environments, and injected at deploy time — not stored in source control (confirmed via a secret-scanning pass across all SureSteps codebases). Sensitive organization fields use field-level encryption. Secrets currently live as environment variables rather than in a dedicated secrets manager; migrating to one, with more granular per-service credential scoping, is on the roadmap.

Operationally, secrets are loaded via environment bindings such as AUTH0_CLIENT_SECRET, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY only at runtime.

Backup & Disaster Recovery

Backups are encrypted at rest with retention of 30 days for production and 7 days for non-production environments. Production protections include deletion protection, final snapshot controls, and reader failover configuration; S3 buckets use versioning. A restore runbook exists, covering database and object-storage recovery as well as application rollback — current RTO/RPO figures are estimates, to be validated through an actual test restore. Cross-region replication is on the roadmap.

Personnel Security

  • Access to production systems is currently limited to the founding team.
  • Onboarding includes security awareness in practice, but there is no tracked standalone awareness program at this time.
  • No formal background check program is in place beyond standard employment vetting processes.

Incident Response

  • Detection: Detection sources include Sentry, Dash0, GitHub Actions deploy history, and Braintrust call traces. CloudTrail is enabled for logging but is not currently used for alerting.
  • Containment: AWS IAM credentials, Auth0 sessions, n8n Cloud API keys, and GitHub Actions secrets can all be individually revoked/rotated through their respective consoles without a deploy. Both deployment targets support fast rollback to a prior version — Elastic Beanstalk can redeploy a previous application version, and Fly.io can roll back to a previous release.
  • Notification: SureSteps targets notification without undue delay and generally within 72 hours after confirming an incident involving customer data.
  • Caveats: Initial timelines are based on incident confirmation, not proof of full compromise. This is a floor to revisit as detection capability matures, not a number chosen independently of what the system can actually catch.

Architecture — Web App

The web application serves authenticated customer interactions, enforces tenant-aware authorization, and communicates with the API over TLS.

HTTPS

browser-direct OAuth/session

browser-direct WebRTC media
(API issues the connection token beforehand)

browser-direct error events

SureSteps Web App
browser

SureSteps API

Identity Provider
login/session

Media/Communications Service
video/voice

Observability Service
error reporting

Architecture — API

The API layer enforces authorization checks, policy logic, and request validation while integrating with managed services and AI providers.

token get/refresh, TLS 1.2+

query, using broker-issued token, TLS 1.2+

API calls in / provisioning out, TLS 1.2+

direct connection (AWS network)

chat/RAG prompts, TLS 1.2+

proxied call

connection token issuance

SureSteps API

Customer CRM
(Salesforce-based)

OAuth Token Broker

Workflow Automation Platform
per-org instances

Database
system of record

Object Storage
file & media blobs

Vector Search
knowledge-base index

Braintrust
LLM proxy + tracing

Anthropic Claude
Sonnet 4.6 / Haiku 4.5

Media/Communications Service
connection token issuance

Architecture — Job Worker

Background workers process asynchronous tasks, execute workflow steps, and emit traceable telemetry for reliability and auditability.

no direct network path
(runs outside the primary cloud account)

summarization/captioning, TLS 1.2+

audio content, TLS 1.2+

text content, TLS 1.2+

Job Worker

Zero Trust Network Tunnel

Database

Object Storage

Vector Search

Braintrust
LLM proxy + tracing

Transcription Service

Embeddings Service

Architecture — Exclusive vs. Shared with Exact Vendors

ComponentCalls ExclusivelyShares With
Web AppAuth0 (identity provider), Sentry (observability)LiveKit (media service; API issues the token)
APINango (OAuth broker), SiteTracker/Salesforce (customer CRM), n8n Cloud (workflow automation), LiveKit (token issuance)Postgres (database), S3 (object storage), Qdrant (vector search), Braintrust → Claude
Job WorkerAssemblyAI (transcription), Voyage AI (embeddings), Cloudflare Access (Zero Trust tunnel)Postgres, S3, Qdrant, Braintrust → Claude