SureSteps Trust CenterDeep Dive
Private distribution. This document is intended for customer security and procurement review under applicable confidentiality terms.
Subprocessors
SureSteps maintains a subprocessors register and provides at least 14 days' written notice (email to the customer's designated contact) before engaging a new subprocessor that will process customer data. This list reflects core production services used for application delivery, AI features, logging, monitoring, and customer communication.
| Vendor | Category | Purpose | Data Handling Summary | SOC 2 / ISO Status | DPA |
|---|---|---|---|---|---|
| AWS | Infrastructure | Primary cloud hosting | Compute, storage, networking, logs, and backups | SOC 2 Type II, ISO 27001 (published) | Y — AWS's standard DPA covers all AWS services in use |
| Anthropic | AI Model | LLM inference | Prompt/response processing with provider retention controls | SOC 2 Type II (published) | Y — retains API inputs/outputs for up to 7 days, solely for abuse prevention/safety monitoring; not used for training |
| Braintrust | AI Observability | LLM evaluation and tracing | Evaluation traces and quality telemetry | SOC 2 Type II, currently valid (report available under NDA); ISO 27001 not published | Y — executable on request. Separately retains full prompt/response traces for up to 14 days, for logging/abuse-prevention/safety purposes only, not training |
| n8n | Workflow | Automation orchestration | Task payloads and workflow metadata | SOC 2 Type II (full report for enterprise customers, SOC 3 summary otherwise); ISO 27001 not published | Y — published at n8n.io/legal/data-processing-agreement |
| Nango | Integrations | OAuth and connector sync | Connection tokens and integration metadata | SOC 2 Type II; ISO 27001 not published | Y — auto-applies to cloud accounts |
| Auth0 | Identity | Authentication and user sessions | User identity attributes and auth logs | SOC 2 Type II (published) | Y — Auth0's standard DPA |
| SendGrid | Communications | Transactional email delivery | Recipient email and message metadata | SOC 2 Type II (published) | Y — Twilio/SendGrid's standard DPA |
| PostHog | Product Analytics | Usage analytics | Event-level product interaction telemetry | SOC 2 Type II (published report); ISO 27001 not published | Y — published in their Trust Center |
| Qdrant | Vector Database | Retrieval and semantic search | Embeddings and scoped vector records | SOC 2 Type II confirmed; ISO 27001 status not corroborated on Qdrant's own pages despite third-party claims | Y — published at cloud.qdrant.io/dpa |
| Fly.io | Edge Runtime | Service deployment footprint | Service runtime and network metadata | SOC 2 Type II; underlying datacenters are ISO 27001-certified facilities, not an org-level Fly.io certification | Y — pre-signed, activates on customer signature |
| Cloudflare | Network Security | WAF/CDN and traffic controls | Request metadata and edge filtering data | SOC 2 Type II, ISO 27001 (published) | Y — Cloudflare's standard DPA |
| Sentry | Monitoring | Error tracking | Error payloads, stack traces, issue metadata | SOC 2 Type II (published) | Y — Sentry's standard DPA |
| Dash0 | Observability | Operational telemetry | Metrics, logs, and traces | SOC 2 Type II; ISO 27001 in progress, not yet certified | Y — published at dash0.com/policies/dpa |
| LiveKit | Realtime Media | Audio/video transport | Realtime stream metadata and session controls | SOC 2 Type II; ISO 27001 in progress, not yet certified (also pursuing PCI DSS) | Y — available; LiveKit maintains its own public subprocessor list |
| AssemblyAI | Speech AI | Transcription | Audio snippets and transcription outputs | SOC 2 Type II (all Trust Service Criteria); ISO 27001 certified | Y — published, auto-incorporated into their ToS |
| Voyage AI | Embeddings | Embedding generation | Text segments transformed to embeddings | Not confirmed for the standalone product following the 2025 MongoDB acquisition — parent MongoDB holds SOC 2, but extension to Voyage AI specifically isn't publicly documented | Y — published at voyageai.com/dpa |
| Cohere | AI Model | Supplementary model services | Prompt/response processing under provider terms | SOC 2 Type II (audited annually); ISO 27001 and ISO 42001 certified | Y — available on request via direct contact, not a self-serve download |
Secrets & API Key Management
Secrets and variables are managed in GitHub Actions, scoped by dev and prod environments, and injected at deploy time — not stored in source control (confirmed via a secret-scanning pass across all SureSteps codebases). Sensitive organization fields use field-level encryption. Secrets currently live as environment variables rather than in a dedicated secrets manager; migrating to one, with more granular per-service credential scoping, is on the roadmap.
Operationally, secrets are loaded via environment bindings such as AUTH0_CLIENT_SECRET, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY only at runtime.
Backup & Disaster Recovery
Backups are encrypted at rest with retention of 30 days for production and 7 days for non-production environments. Production protections include deletion protection, final snapshot controls, and reader failover configuration; S3 buckets use versioning. A restore runbook exists, covering database and object-storage recovery as well as application rollback — current RTO/RPO figures are estimates, to be validated through an actual test restore. Cross-region replication is on the roadmap.
Personnel Security
- Access to production systems is currently limited to the founding team.
- Onboarding includes security awareness in practice, but there is no tracked standalone awareness program at this time.
- No formal background check program is in place beyond standard employment vetting processes.
Incident Response
- Detection: Detection sources include Sentry, Dash0, GitHub Actions deploy history, and Braintrust call traces. CloudTrail is enabled for logging but is not currently used for alerting.
- Containment: AWS IAM credentials, Auth0 sessions, n8n Cloud API keys, and GitHub Actions secrets can all be individually revoked/rotated through their respective consoles without a deploy. Both deployment targets support fast rollback to a prior version — Elastic Beanstalk can redeploy a previous application version, and Fly.io can roll back to a previous release.
- Notification: SureSteps targets notification without undue delay and generally within
72 hoursafter confirming an incident involving customer data. - Caveats: Initial timelines are based on incident confirmation, not proof of full compromise. This is a floor to revisit as detection capability matures, not a number chosen independently of what the system can actually catch.
Architecture — Web App
The web application serves authenticated customer interactions, enforces tenant-aware authorization, and communicates with the API over TLS.
Architecture — API
The API layer enforces authorization checks, policy logic, and request validation while integrating with managed services and AI providers.
Architecture — Job Worker
Background workers process asynchronous tasks, execute workflow steps, and emit traceable telemetry for reliability and auditability.
Architecture — Exclusive vs. Shared with Exact Vendors
| Component | Calls Exclusively | Shares With |
|---|---|---|
| Web App | Auth0 (identity provider), Sentry (observability) | LiveKit (media service; API issues the token) |
| API | Nango (OAuth broker), SiteTracker/Salesforce (customer CRM), n8n Cloud (workflow automation), LiveKit (token issuance) | Postgres (database), S3 (object storage), Qdrant (vector search), Braintrust → Claude |
| Job Worker | AssemblyAI (transcription), Voyage AI (embeddings), Cloudflare Access (Zero Trust tunnel) | Postgres, S3, Qdrant, Braintrust → Claude |