Authenticated product access
ProfitZ uses Stack Auth for account authentication. Active company, audit, report, and advisor routes enforce signed-in access and company ownership checks.
This page describes controls currently implemented in ProfitZ. Provider certifications are not presented as ProfitZ certifications, and security claims are kept separate from future roadmap work.
ProfitZ is designed for ordinary business-operating information. Do not upload specially regulated or highly sensitive personal data. Ask security@profitz.ai before use when your organization has contractual or regulatory requirements.
Implemented today
ProfitZ uses Stack Auth for account authentication. Active company, audit, report, and advisor routes enforce signed-in access and company ownership checks.
The hosted application and its managed providers use HTTPS/TLS for network transport. Storage-layer encryption is operated by the relevant cloud provider.
Application workloads run on Vercel, core relational data is stored in Neon Postgres, and generated files may use Vercel Blob. Each provider maintains its own controls and attestations.
Content is sent to the AI provider needed for a selected feature. ProfitZ does not train its own foundation model on customer content. Provider terms and retention rules still apply.
The repository runs automated authorization inventories, tenant-boundary tests, dependency scans, and production-build checks before controlled releases.
Security reports go to security@profitz.ai. Reports are triaged, contained, investigated, and communicated according to impact and applicable notice requirements.
No public SLA
No unsupported uptime or response-time promise.
No session replay
Mixpanel replay is disabled; optional analytics requires a choice.
One intake
Security reports are centralized at security@profitz.ai.
ProfitZ does not currently represent itself as SOC 2 audited or ISO 27001 certified. Some infrastructure providers publish their own certifications. Those attestations apply to the provider and do not automatically certify ProfitZ.
Do not submit passwords, full payment-card numbers, government identifiers, protected health information, or data that requires a specialized regulatory agreement. ProfitZ is not currently offered under a BAA or as a PCI card-data environment.
Authorized users in your account can access the product data available to that account. Service providers process data to operate their assigned feature. Limited support or engineering access may occur when needed to operate, secure, troubleshoot, or comply with law.
Audit transcripts, business context, documents, or derived data may be sent to OpenAI, xAI, Google, or Anthropic depending on the feature and configuration. ProfitZ does not promise that every provider has identical retention terms. See the subprocessor disclosure for the current roles.
Yes. Workspace owners can remove companies in the product, and broader verified requests can be sent to privacy@profitz.ai. Some records may remain where required for billing, fraud prevention, legal obligations, provider retention, or backup rotation. We do not promise an unsupported fixed deletion window.
No public uptime, support-response, or service-credit SLA applies. Any contractual commitment must be stated in a separate written order signed by ProfitZ.
Include a clear reproduction, affected URL or feature, potential impact, and a safe way to contact you. Do not access another customer's data or disrupt service.
security@profitz.aiReview the current categories of data, purposes, retention limits, service-provider roles, AI limitations, and request channels.
Open the Legal Center