Skip to main content
Trust & Compliance

Procurement-grade trust.
Documented. Audited. Public.

Every commitment we make to enterprise evaluators, government agencies, and institutional partners - with plain-English documentation, downloadable artifacts, and live audit status.

Authentication

Authentication and access control

Authentication runs on Supabase, our SOC 2 Type II certified backbone provider. Account credentials and session tokens never leave their infrastructure.

  • Multi-factor authentication on every plan
    Authenticator-app (TOTP) enrollment. Eight single-use recovery codes, stored only in securely hashed form, never in plain text.
  • Step-up verification for sensitive operations
    Billing changes, member removal, and platform-administrator actions require a fresh authentication factor - not a stored cookie. Stale sessions cannot perform these operations.
  • Audit logging on every authentication event
    Sign-in, sign-out, MFA enrollment and verification, recovery-code use, and administrator actions are recorded with timestamp, actor, and target. Visible to organization administrators; exportable on Enterprise.
  • Org-wide MFA enforcement available on Pro and Enterprise
    Administrators can require all members to enroll a second factor before accessing the dashboard.
  • Sole-administrator monitoring
    A daily check flags organizations where a single administrator holds MFA without recovery code coverage, surfacing the lockout risk before it becomes a support ticket.
Accessibility

WCAG 2.2 Level AA conformance

Validated through automated accessibility testing on every release and documented in a formal VPAT. Marketing pages, authenticated dashboard, and every interactive component.

WCAG 2.2 Level AA - Supports with Documented Limitations
55
Success criteria evaluated
3
Partially Supports
6
Not Applicable

Last updated: 2026-04-30. Regenerated per major auth UI release.

Known Limitations

Three areas carry “Partially Supports” status due to third-party component constraints. Full details, including remediation plans, are documented in the VPAT.

  • Workflow canvas editor - The drag-based automation canvas has limited keyboard navigation for repositioning items. Surrounding controls and configuration panels remain fully accessible.
  • Dashboard widget layout - Repositioning dashboard widgets requires drag interaction. Widget content and all data remain fully keyboard-accessible.
  • Third-party embeds - Stripe’s payment form and Supabase’s sign-in components are maintained by their respective vendors. Both vendors publish their own accessibility documentation.
Data Retention & Deletion

Org admins control deletion. Every action is reversible inside the recovery window.

When you delete a record, it leaves active views immediately and is retained for a recovery window before automatic purge. For GDPR / CCPA right-to-erasure, your admin can flag any record for 7-day fast-track deletion that overrides normal retention.

Soft delete with 7-30 day recovery window
Operational data retained 7 days
Core records retained 30 days
Fast-track GDPR/CCPA deletion in 7 days
Hash-chained audit trail for every action
Org-side recovery view at /dashboard/trash

Full technical detail on how retention and recovery work is available in our documentation on request.

Security

SOC 2 Type II controls, in-progress audit

PCI DSS scope is limited to SAQ A (Stripe-hosted checkout). Additional security documentation is available under NDA.

Summary of security controls and their current status
ControlStatus
SOC 2 Type II (TappHQ)Observation period - Type II report targeted Q4 2026
SOC 2 Type II (Supabase backbone)Independently certified - authentication infrastructure
PCI DSSSAQ A (Stripe-hosted checkout)
Data encryptionAES-256-GCM at rest, TLS 1.3 in transit
Personal data protectionField-level encryption, with SHA-256 hashing for sensitive identifiers
Penetration testingScheduled (summary available under NDA)
Upload protectionFile type verification, local malware scanning, reputation check against known-malware hashes (MetaDefender Cloud), image injection screening

External pen test scheduled. Engagement timeline available on request - contact compliance@tapphq.com.

SOC 2 Type II - In Progress

Type II observation window underway. Control matrix published; audit readout targeted post-observation.

As of 2026-04-21. Attestation letters available on request at compliance@tapphq.com.

Upload Protection

  • File type verification - every upload is inspected to confirm its real type matches what it claims to be; dangerous file types (.exe, .bat, .jar) are blocked at upload
  • Malware scanning - every file is scanned at upload, and its fingerprint is checked against a database of known malware (MetaDefender Cloud); infected files are blocked from download
  • Image screening - uploaded images are checked for hidden text designed to manipulate the AI, protecting TappIQ from tampered files

Security inquiries: compliance@tapphq.com

Certifications

Compliance and certifications

Active certifications, audit progress, and roadmap items - disclosed honestly so procurement evaluators can size risk without requesting follow-up.

SOC 2 Type II

In observation period

TappHQ is in active SOC 2 Type II observation, with evidence collection underway. Type II report targeted Q4 2026. Authentication backbone (Supabase) is independently SOC 2 Type II certified. Audit progress available under NDA on request - compliance@tapphq.com.

GDPR

Compliant

Data Processing Agreement available. EU data subjects supported with full access, rectification, erasure, and portability rights.

CCPA / CPRA

Compliant

California Consumer Privacy Act compliant. Privacy notice at /legal/privacy.

WCAG 2.2 AA

Conformance documented

Conformance documented in VPAT 2.5 WCAG Edition (download above).

HIPAA

Roadmap

HIPAA BAA support is on the roadmap. Healthcare-adjacent nonprofit data handling is informed by HIPAA principles today; formal BAA coverage will follow SOC 2 Type II.

ISO 27001

Roadmap

ISO 27001 certification is on the roadmap, sequenced after SOC 2 Type II. Information security management aligned with ISO/IEC 27001:2022 controls.

Documentation

Compliance documentation

Procurement-ready artifacts and policy links in one place. DPA available on request for enterprise and institutional customers.

FAQ

Frequently asked questions

Procurement self-service. Questions evaluators ask most often, answered without an NDA - with a path to deeper detail when one is required.

Who provides authentication for TappHQ?

Supabase, Inc. provides our authentication backbone. Supabase holds an independent SOC 2 Type II certification covering authentication infrastructure. Their Data Processing Agreement is at supabase.com/legal/dpa.

TappHQ itself is in active SOC 2 Type II observation, with Type II report targeted Q4 2026. Audit progress available under NDA - compliance@tapphq.com.

Is multi-factor authentication available?

Yes, on every plan. Users enroll a TOTP authenticator app (Google Authenticator, 1Password, Authy, and others). Eight single-use recovery codes are generated at enrollment and stored hashed. Pro and Enterprise organizations can require MFA for all members.

How are sensitive operations protected?

High-impact operations - billing changes, member removal, platform-administrator actions - require a fresh MFA verification (step-up). Stale sessions cannot perform these operations.

What audit logging is available?

Authentication events (sign-in, sign-out, MFA enrollment, MFA verification, recovery code use, administrator actions) are logged with timestamp, actor, and target. Organization administrators see their org's events. Enterprise plans support audit log export.

What is TappHQ's SOC 2 status?

TappHQ is in active SOC 2 Type II observation period. An independent auditor is engaged and evidence collection is underway. Type II report is targeted for Q4 2026. Authentication infrastructure (Supabase) is independently SOC 2 Type II certified today.

Procurement evaluators can request audit progress detail, current control coverage, and observation-window evidence sample under NDA - contact compliance@tapphq.com.

ISO 27001 and HIPAA BAA support are on the roadmap, sequenced after SOC 2 Type II.

Where is data stored?

Application data is stored with Supabase in the United States (US East). File storage is in the same region. See our subprocessor list for full data flow.

Roadmap

Planned compliance additions

Artifacts queued for publication as TappHQ completes its audit and certification cycle.

  • SOC 2 Type II audit report (first-year audit in progress)
  • Penetration testing summary (redacted version available under NDA)
  • Subprocessor list (DPA appendix)
  • SIG Lite questionnaire responses
  • ISO 27001 gap assessment
Trust Center

Procurement question we haven't answered?

Request our full security review packet, vendor DPAs, and compliance artifact bundle. We acknowledge requests within three business days. No NDA required for the overview.