Trust and Security
We work inside client systems and handle financial, email, project, and operational data. That level of access sets the bar for how we run security, and we hold ourselves to it. This page states what is true today, backed by evidence you can request. Anything that is not issued, measured, or documented is not on this page.
Compliance Status
Our SOC 2 Type II examination is in progress with Sensiba LLP, an AICPA-licensed firm. The observation window runs 1 June to 31 August 2026, and the report will be available under NDA once it is issued. We use Vanta for continuous control monitoring, and our live Trust Center is the single source of truth for our current status and evidence.
Request our SOC 2 report and security documentation under NDA through the Trust Center or at security@1404.io.
How We Protect Your Data
Encryption
Data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256 using AWS-managed keys (KMS).
Access
We enforce least-privilege, role-based access with MFA on administrative access, SSH key-only login, and hardware MFA on the AWS root account. Administrative access runs over a zero-trust private network, and access is reviewed periodically.
Hosting and Isolation
Client environments run on AWS in US regions (us-east-1 and us-east-2), with per-client isolation designed in at the compute, IAM, key-management, and storage layers.
Backups and Recovery
Databases are backed up within AWS with point-in-time recovery and retained in a separate AWS Backup vault, with an encrypted copy replicated to a second AWS region (us-east-2) for disaster recovery. Our disaster recovery plan targets a 24-hour recovery time and recovery point objective, and it is tested at least annually.
Subprocessors
These third parties may process client data in the course of delivering our services. AWS, Anthropic, Sentry, GitHub, and Tailscale are 1404 subprocessors; Microsoft 365, Google Workspace, Intuit/QuickBooks, and Smartsheet are client-owned systems we integrate with read-only (your own vendors), listed here for transparency.
Last reviewed July 2026
| Provider | Service | Data Processed | Location |
|---|---|---|---|
| AWS | Infrastructure hosting | All client data | US (us-east-1, us-east-2) |
| Anthropic | Claude AI API | Prompts & responses (30-day retention, training opt-out) | US |
| Microsoft 365 | Email, files, calendar integration | Per client | US |
| Google Workspace | Email, files, calendar integration | Per client | US |
| GitHub | Source code hosting | Application code | US |
| Intuit / QuickBooks | Accounting integration | Financial data (per client) | US |
| Smartsheet | Project management integration | Project data (per client) | US |
| Sentry | Application error monitoring | Error telemetry (PII-scrubbed) | US |
| Tailscale | Administrative VPN | No client data transits | US |
Privacy and Legal
Our Privacy Policy and Terms of Service are published. A GDPR-aligned Data Processing Agreement and a HIPAA Business Associate Agreement template are available on request.
Documents Available on Request
The following are available under NDA:
- • SOC 2 Type II report, once issued
- • Data Processing Agreement (DPA)
- • HIPAA Business Associate Agreement (BAA) template
Request access through our Trust Center or by emailing security@1404.io.
Security Contact
Report a security concern, vulnerability, or documentation request to:
We acknowledge reports promptly and route them through our Incident Response Plan.