Trust & Security

Your data, handled
the way we'd want
ours handled.

Launch at Dawn is built on a simple rule: every number we show you is backed by evidence, and every piece of data you trust us with is protected with the same care. Here's exactly how we do it.

01

Passwordless sign-in

You sign in with a magic link emailed to you — we never create or store a password for you, and there's no credential to steal.

02

Credentials encrypted at rest

Third-party tokens (GitHub, GitLab, WordPress, Slack) are encrypted with AES-256-GCM before they ever touch the database.

03

Row-level isolation

Your data is scoped to your account with database Row-Level Security, so each user only sees their own businesses and reports.

04

You own your data

Export your data or delete your account and its data at any time — GDPR data-portability (Art. 20) and erasure (Art. 17) are built in.

05

Safer AI-agent actions

Repo publishing uses a strict path allowlist, content validation, size limits, and draft-first PRs — it never writes executable code or touches your main branch directly.

06

Every answer is evidence

Every score is backed by the verbatim AI responses behind it. We show you the source of every number rather than asking you to trust a black box.

How we keep it safe

Built on managed, hardened infrastructure — not a basement server.

We run on industry-standard managed cloud providers and rely on platform-level encryption, auth, and monitoring rather than rolling our own. Here is the stack and where each responsibility lives.

Hosting

Vercel (Next.js serverless), with PostgreSQL + Auth on Supabase

Payments

Stripe — your card details are never stored on our servers

Email

Transactional email via Resend

In transit

All traffic is encrypted over HTTPS/TLS; data at rest is encrypted by our hosting and database providers

Sign-in

Passwordless email magic link with short-lived HTTP-only, Secure session cookies

Access control

Database Row-Level Security plus admin email allowlists and CRON-secret-gated jobs

Sub-processors

Who touches your data — and where.

ProcessorRole
SupabaseDatabase, authentication, file storage
StripePayments & billing
ResendTransactional email
VercelHosting, edge functions, analytics
AI model providersAggregated answers for visibility scans (OpenAI, Anthropic, Google, Perplexity, Groq, Mistral, DeepSeek, xAI, OpenRouter)
Google AnalyticsOptional GA4 connection for your own traffic data

AI visibility scans query model providers worldwide, so prompts may be processed outside the EU/UK. A full list of processors and the terms governing them is in our Data Processing Agreement.

Compliance status

Straight answers on enterprise readiness.

We don't want to surprise you later. If your procurement team needs a specific certification, we'd rather tell you upfront where we are than overstate it.

Not yet in place

  • SOC 2 or ISO 27001 certification
  • SSO / SAML / single sign-on
  • Custom backup & disaster-recovery SLA
  • A published penetration-testing cadence

Want one of these for your account? Tell us at security@launchatdawn.com — we plan the roadmap from what real buyers ask for.