Procurement-grade trust.
Documented. Audited. Public.
Every commitment we make to enterprise evaluators, government agencies, and institutional partners - with plain-English documentation, downloadable artifacts, and live audit status.
Five deep-dives for procurement
Each section is a detailed, plain-English deep dive. Built for evaluators who need more than marketing copy.
Authentication and access control
Authentication runs on Supabase, our SOC 2 Type II certified backbone provider. Account credentials and session tokens never leave their infrastructure.
- Multi-factor authentication on every planAuthenticator-app (TOTP) enrollment. Eight single-use recovery codes, stored only in securely hashed form, never in plain text.
- Step-up verification for sensitive operationsBilling changes, member removal, and platform-administrator actions require a fresh authentication factor - not a stored cookie. Stale sessions cannot perform these operations.
- Audit logging on every authentication eventSign-in, sign-out, MFA enrollment and verification, recovery-code use, and administrator actions are recorded with timestamp, actor, and target. Visible to organization administrators; exportable on Enterprise.
- Org-wide MFA enforcement available on Pro and EnterpriseAdministrators can require all members to enroll a second factor before accessing the dashboard.
- Sole-administrator monitoringA daily check flags organizations where a single administrator holds MFA without recovery code coverage, surfacing the lockout risk before it becomes a support ticket.
WCAG 2.2 Level AA conformance
Validated through automated accessibility testing on every release and documented in a formal VPAT. Marketing pages, authenticated dashboard, and every interactive component.
Last updated: 2026-04-30. Regenerated per major auth UI release.
Known Limitations
Three areas carry “Partially Supports” status due to third-party component constraints. Full details, including remediation plans, are documented in the VPAT.
- Workflow canvas editor - The drag-based automation canvas has limited keyboard navigation for repositioning items. Surrounding controls and configuration panels remain fully accessible.
- Dashboard widget layout - Repositioning dashboard widgets requires drag interaction. Widget content and all data remain fully keyboard-accessible.
- Third-party embeds - Stripe’s payment form and Supabase’s sign-in components are maintained by their respective vendors. Both vendors publish their own accessibility documentation.
Org admins control deletion. Every action is reversible inside the recovery window.
When you delete a record, it leaves active views immediately and is retained for a recovery window before automatic purge. For GDPR / CCPA right-to-erasure, your admin can flag any record for 7-day fast-track deletion that overrides normal retention.
Full technical detail on how retention and recovery work is available in our documentation on request.
Every policy, published and versioned
All policies are available without authentication. Versioned in git, reviewed by counsel, and updated on cadence.
Terms of Service
Platform usage terms and conditions
Privacy Policy
How we collect, use, and protect data
Cookie Policy
Cookie usage and consent preferences
Data Processing Agreement
DPA for enterprise and institutional customers
AI Disclaimer
How AI is used across the platform
Acceptable Use Policy
Permitted and prohibited platform usage
SOC 2 Type II controls, in-progress audit
PCI DSS scope is limited to SAQ A (Stripe-hosted checkout). Additional security documentation is available under NDA.
| Control | Status |
|---|---|
| SOC 2 Type II (TappHQ) | Observation period - Type II report targeted Q4 2026 |
| SOC 2 Type II (Supabase backbone) | Independently certified - authentication infrastructure |
| PCI DSS | SAQ A (Stripe-hosted checkout) |
| Data encryption | AES-256-GCM at rest, TLS 1.3 in transit |
| Personal data protection | Field-level encryption, with SHA-256 hashing for sensitive identifiers |
| Penetration testing | Scheduled (summary available under NDA) |
| Upload protection | File type verification, local malware scanning, reputation check against known-malware hashes (MetaDefender Cloud), image injection screening |
External pen test scheduled. Engagement timeline available on request - contact compliance@tapphq.com.
Upload Protection
- File type verification - every upload is inspected to confirm its real type matches what it claims to be; dangerous file types (.exe, .bat, .jar) are blocked at upload
- Malware scanning - every file is scanned at upload, and its fingerprint is checked against a database of known malware (MetaDefender Cloud); infected files are blocked from download
- Image screening - uploaded images are checked for hidden text designed to manipulate the AI, protecting TappIQ from tampered files
Security inquiries: compliance@tapphq.com
Compliance and certifications
Active certifications, audit progress, and roadmap items - disclosed honestly so procurement evaluators can size risk without requesting follow-up.
SOC 2 Type II
In observation period
TappHQ is in active SOC 2 Type II observation, with evidence collection underway. Type II report targeted Q4 2026. Authentication backbone (Supabase) is independently SOC 2 Type II certified. Audit progress available under NDA on request - compliance@tapphq.com.
GDPR
Compliant
Data Processing Agreement available. EU data subjects supported with full access, rectification, erasure, and portability rights.
WCAG 2.2 AA
Conformance documented
Conformance documented in VPAT 2.5 WCAG Edition (download above).
HIPAA
Roadmap
HIPAA BAA support is on the roadmap. Healthcare-adjacent nonprofit data handling is informed by HIPAA principles today; formal BAA coverage will follow SOC 2 Type II.
ISO 27001
Roadmap
ISO 27001 certification is on the roadmap, sequenced after SOC 2 Type II. Information security management aligned with ISO/IEC 27001:2022 controls.
Compliance documentation
Procurement-ready artifacts and policy links in one place. DPA available on request for enterprise and institutional customers.
- Subprocessor list - third-party services that process customer data
- Privacy policy - how we collect, use, and protect data
- VPAT 2.5 WCAG Edition (2026-04-30) - accessibility conformance per criterion
- Data Processing Agreement - available on request for enterprise and institutional customers (compliance@tapphq.com)
Frequently asked questions
Procurement self-service. Questions evaluators ask most often, answered without an NDA - with a path to deeper detail when one is required.
Who provides authentication for TappHQ?
Supabase, Inc. provides our authentication backbone. Supabase holds an independent SOC 2 Type II certification covering authentication infrastructure. Their Data Processing Agreement is at supabase.com/legal/dpa.
TappHQ itself is in active SOC 2 Type II observation, with Type II report targeted Q4 2026. Audit progress available under NDA - compliance@tapphq.com.
Is multi-factor authentication available?
Yes, on every plan. Users enroll a TOTP authenticator app (Google Authenticator, 1Password, Authy, and others). Eight single-use recovery codes are generated at enrollment and stored hashed. Pro and Enterprise organizations can require MFA for all members.
How are sensitive operations protected?
High-impact operations - billing changes, member removal, platform-administrator actions - require a fresh MFA verification (step-up). Stale sessions cannot perform these operations.
What audit logging is available?
Authentication events (sign-in, sign-out, MFA enrollment, MFA verification, recovery code use, administrator actions) are logged with timestamp, actor, and target. Organization administrators see their org's events. Enterprise plans support audit log export.
What is TappHQ's SOC 2 status?
TappHQ is in active SOC 2 Type II observation period. An independent auditor is engaged and evidence collection is underway. Type II report is targeted for Q4 2026. Authentication infrastructure (Supabase) is independently SOC 2 Type II certified today.
Procurement evaluators can request audit progress detail, current control coverage, and observation-window evidence sample under NDA - contact compliance@tapphq.com.
ISO 27001 and HIPAA BAA support are on the roadmap, sequenced after SOC 2 Type II.
Where is data stored?
Application data is stored with Supabase in the United States (US East). File storage is in the same region. See our subprocessor list for full data flow.
Planned compliance additions
Artifacts queued for publication as TappHQ completes its audit and certification cycle.
- SOC 2 Type II audit report (first-year audit in progress)
- Penetration testing summary (redacted version available under NDA)
- Subprocessor list (DPA appendix)
- SIG Lite questionnaire responses
- ISO 27001 gap assessment
Procurement question we haven't answered?
Request our full security review packet, vendor DPAs, and compliance artifact bundle. We acknowledge requests within three business days. No NDA required for the overview.