Trust & Security
Your data, handled
the way we'd want
ours handled.
Launch at Dawn is built on a simple rule: every number we show you is backed by evidence, and every piece of data you trust us with is protected with the same care. Here's exactly how we do it.
01
Passwordless sign-in
You sign in with a magic link emailed to you — we never create or store a password for you, and there's no credential to steal.
02
Credentials encrypted at rest
Third-party tokens (GitHub, GitLab, WordPress, Slack) are encrypted with AES-256-GCM before they ever touch the database.
03
Row-level isolation
Your data is scoped to your account with database Row-Level Security, so each user only sees their own businesses and reports.
04
You own your data
Export your data or delete your account and its data at any time — GDPR data-portability (Art. 20) and erasure (Art. 17) are built in.
05
Safer AI-agent actions
Repo publishing uses a strict path allowlist, content validation, size limits, and draft-first PRs — it never writes executable code or touches your main branch directly.
06
Every answer is evidence
Every score is backed by the verbatim AI responses behind it. We show you the source of every number rather than asking you to trust a black box.
How we keep it safe
Built on managed, hardened infrastructure — not a basement server.
We run on industry-standard managed cloud providers and rely on platform-level encryption, auth, and monitoring rather than rolling our own. Here is the stack and where each responsibility lives.
Hosting
Vercel (Next.js serverless), with PostgreSQL + Auth on Supabase
Payments
Stripe — your card details are never stored on our servers
Transactional email via Resend
In transit
All traffic is encrypted over HTTPS/TLS; data at rest is encrypted by our hosting and database providers
Sign-in
Passwordless email magic link with short-lived HTTP-only, Secure session cookies
Access control
Database Row-Level Security plus admin email allowlists and CRON-secret-gated jobs
Sub-processors
Who touches your data — and where.
| Processor | Role |
|---|---|
| Supabase | Database, authentication, file storage |
| Stripe | Payments & billing |
| Resend | Transactional email |
| Vercel | Hosting, edge functions, analytics |
| AI model providers | Aggregated answers for visibility scans (OpenAI, Anthropic, Google, Perplexity, Groq, Mistral, DeepSeek, xAI, OpenRouter) |
| Google Analytics | Optional GA4 connection for your own traffic data |
AI visibility scans query model providers worldwide, so prompts may be processed outside the EU/UK. A full list of processors and the terms governing them is in our Data Processing Agreement.
Compliance status
Straight answers on enterprise readiness.
We don't want to surprise you later. If your procurement team needs a specific certification, we'd rather tell you upfront where we are than overstate it.
Not yet in place
- SOC 2 or ISO 27001 certification
- SSO / SAML / single sign-on
- Custom backup & disaster-recovery SLA
- A published penetration-testing cadence
Want one of these for your account? Tell us at security@launchatdawn.com — we plan the roadmap from what real buyers ask for.