Information Security and Access Control Policy

Effective Date: April 10, 2026  •  Version 1.0

This Information Security and Access Control Policy establishes the framework by which OwnerClone identifies, mitigates, and monitors information security risks relevant to our business and the consumer and financial data we process. This Policy applies to all systems, personnel, and data assets operated by OwnerClone, Inc.

1. Purpose

This Policy fulfills requirements under our agreements with third-party data providers including Plaid and applies to all production systems, databases, infrastructure, and personnel with access to consumer or financial data.

2. Scope

  • All production systems, databases, and infrastructure operated by OwnerClone
  • All consumer financial data, personal information, and business data processed through the platform
  • All personnel with access to production systems, including contractors and third-party service providers
  • Data received from third-party providers including Plaid, Stripe, and payment processors

3. Information Security Program

3.1 Infrastructure Security

  • All application infrastructure is hosted on Vercel, which enforces TLS 1.2 or higher on all data transmissions.
  • All database infrastructure is hosted on Supabase (AWS us-east-1), which provides AES-256 encryption at rest by default.
  • No sensitive consumer data is stored on local developer machines or unmanaged infrastructure.
  • All third-party API credentials and secrets are stored as environment variables in Vercel's encrypted secret management system and never committed to source code.

3.2 Access Control

  • Role-Based Access Control (RBAC) is enforced at the database layer via Supabase Row Level Security (RLS) policies, ensuring users can only access data belonging to their own restaurant organization.
  • Production database access is limited to authorized personnel only via Supabase dashboard authentication.
  • OAuth 2.0 tokens are used for all non-human system authentication and third-party API integrations.
  • Supabase Auth serves as the centralized identity and access management system for all platform users.
  • All API routes validate user authentication and authorization before processing any request.

3.3 Data Transmission Security

  • All data transmitted between clients and servers is encrypted using TLS 1.2 or higher, enforced by Vercel's edge network.
  • All data transmitted to and from third-party providers including Plaid is transmitted over encrypted connections.
  • Sensitive credentials and API keys are never transmitted via email or unencrypted channels.

3.4 Application Security

  • Source code is maintained in a private GitHub repository with access limited to authorized personnel.
  • Vercel auto-deploys are triggered only from authorized repository branches.
  • Environment variables and secrets are managed exclusively through Vercel's encrypted environment variable system.
  • Dependencies are monitored for known vulnerabilities via GitHub's built-in dependency scanning.

3.5 Incident Response

  • Security incidents involving consumer data are reported to affected parties and relevant authorities within 72 hours of discovery, in compliance with applicable data breach notification laws.
  • In the event of a Plaid API credential compromise, the Plaid integrations team is notified immediately and compromised credentials are rotated.
  • Incidents are documented, reviewed, and used to improve security controls on an ongoing basis.

4. Risk Identification and Mitigation

OwnerClone continuously identifies and mitigates information security risks through:

  • Regular review of Vercel and Supabase security advisories and platform updates.
  • Monitoring of GitHub dependency alerts for vulnerable packages in the application codebase.
  • Review of Supabase audit logs for unauthorized access attempts.
  • Periodic review of RLS policies and API authorization logic when new features are deployed.
  • Annual review of this Policy and all associated security documentation.

5. Third-Party Provider Security

  • Vercel: SOC 2 Type II certified application hosting and edge network. Enforces TLS on all traffic.
  • Supabase: Hosted on AWS with SOC 2 compliance. Provides encryption at rest, RLS, and audit logging.
  • Plaid: Compliant with GLBA, CCPA, and Dodd-Frank Section 1033. All connections secured via TLS.
  • Stripe: PCI DSS Level 1 certified payment processor.
  • Anthropic: API-based AI processing with zero data retention on API calls per Anthropic's enterprise policy.

6. Access Review and Offboarding

  • Production system access is limited to the founding team only.
  • Third-party contractor access is granted on a least-privilege basis and revoked immediately upon completion of engagement.
  • All access credentials are rotated when personnel changes occur.
  • API keys and access tokens are audited and rotated on a defined schedule or upon suspected compromise.

7. Policy Compliance and Review

This Policy is reviewed at minimum annually and updated whenever significant changes occur to our infrastructure, data processing activities, applicable law, or third-party provider relationships. All personnel with access to production systems are required to be familiar with and comply with this Policy.

Violations of this Policy are treated as serious incidents and may result in immediate revocation of system access.

8. Contact

Security Questions?

Contact us at [email protected] for any questions about our security practices.

View All Legal Documents