Legal · Trust Center
Security
Last updated · 8 October 2026 · The single URL a security team can read end-to-end.
Palanor is built for institutional stewards. Security and governance are not features layered on top of the product — they are the perimeter the product runs inside. This page describes the current posture in plain language. Where we have a specific control, we name it. Where a customer would reasonably expect more than we have today, we say so.
1. Encryption
In transit: TLS 1.2 or higher on every connection. HTTP Strict Transport Security enabled across palanor.com and its active subdomains (app, terminal, hub, api, mcp, developers). Certificates managed by Vercel and Cloudflare; minimum 2048-bit RSA / P-256 ECDSA.
At rest: The Supabase Postgres database and Storage buckets are encrypted at rest by Supabase using AES-256 (AWS-managed keys). Vercel build artifacts and logs are encrypted at rest by Vercel.
Customer LLM keys (BYOLLM): When a customer brings their own LLM provider API key, that key is encrypted application-side with AES-256-GCM (NIST SP 800-38D) before it reaches the database. Each row carries a per-encryption 12-byte IV and 16-byte authentication tag, so any tampering with the stored ciphertext fails the decrypt with a clear error. The master encryption key lives in Vercel’s encrypted environment store and never touches the database. Implementation: src/lib/llm/byollm-crypto.ts.
2. Authentication + access control
Customer authentication: Email + password, or Google, Microsoft or LinkedIn sign-in, via Supabase Auth (managed by Supabase, SOC 2 Type II certified). Passwords must be at least 12 characters with an uppercase letter, a lowercase letter, a number and a symbol, and are checked against known breached passwords; a password that falls below the standard must be replaced at the next sign-in. New accounts must set up a second factor before using Palanor: an authenticator app (TOTP), managed at /account/security. Every account with a second factor holds ten single-use backup codes, stored only as hashes. Organizations can require two-factor for every member. Someone who loses both their device and their codes can recover only through a staff-reviewed process with identity verification, organization confirmation and a 24-hour hold. SMS-based MFA is deliberately not offered — it is the weakest form of MFA and we will not ship it.
Tenant isolation: Every customer table carries Row Level Security policies that enforce organization_id = current_user’s active org. Row Level Security is enforced at the database layer rather than only in application code, so an organization’s rows are not returned to a caller outside that organization. Coverage and policy correctness are reviewed on an ongoing basis.
Palanor employee access: Production access is limited to PALANOR_INTERNAL_EMAILS (today: founder only). All employee operations against the production database route through the Supabase service-role key, which lives only in encrypted server contexts (Vercel env, the founder’s workstation). The anon key, available to browsers, cannot bypass Row Level Security.
Profanity + handle filter: Sign-up handles run through a curated banned-words filter that rejects profanity, slurs, impersonation handles (admin, root, numen, palanor, council), and reserved Council bylines. Source: src/lib/auth/username-filter.ts.
3. Data residency
The Palanor app and database are hosted in the United States (Vercel Edge + Supabase, AWS us-east region). LLM inference runs in the United States via Anthropic. Email delivery runs in the United States via Resend. EU-region hosting is available on request for contracts that require it — please contact privacy@palanor.com with the requirement.
4. AI handling
Palanor uses LLMs (Anthropic Claude is the default; customers may bring their own provider) to compose briefings, score signals, and surface scenarios. Per the Anthropic Commercial Terms in force, prompts and completions sent to the Anthropic API are not used to train Anthropic’s models. The same holds for OpenAI (used for embeddings + news-image generation) and ElevenLabs (used for the Numen voice reader) under their respective commercial terms. We do not train any model on customer data.
The full disclosure of how AI is used inside the product is at /how-we-use-ai.
5. Vendor governance
Every subprocessor Palanor uses is listed at /subprocessors with the service provided, processing location, and data category. Each is contractually bound by a Data Processing Agreement. Customers can subscribe to subprocessor change notifications at privacy@palanor.com and receive at least 30 days’ notice of any change.
6. Vulnerability management
Disclosure: Researchers can report vulnerabilities to security@palanor.com. The full disclosure policy is published in machine-readable form at /.well-known/security.txt. We commit to acknowledge within 3 business days, provide a remediation estimate within 10 business days, and credit reporters on request.
Dependencies: Automated dependency scanning runs continuously via Dependabot on the production repository. Remediation timeframes follow the Vulnerability Management Policy: critical within 7 days, high within 30 days, medium within 90 days, measured from the alert. Where no patched release exists, the exposure is assessed and a documented exception is recorded.
Annual penetration test: An independent third-party penetration test was performed on 23 June 2026 by Workstreet against app.palanor.com (deep scan, 77 tests, unauthenticated). Overall risk rating: Low — zero critical, zero high, zero medium, four low, one informational. All findings were remediated and verified in production on 29 June 2026. The next test is scheduled within twelve months. A summary is available to customers under NDA.
7. Logging + observability
Platform logs (edge, database, authentication, and function logs, including URL, timestamp, IP, user-agent, response status, and user id where applicable) are drained on a recurring schedule to dedicated object storage and retained on a rolling 90-day window, extending beyond the 7-day native retention of the database plan. Application audit events — actor, action, target, and timestamp — are recorded in the production database and retained for the life of the account.
8. Incident response
The incident response posture is detect → triage → contain → eradicate → recover → post-mortem. Customer-affecting incidents are disclosed within 72 hours of confirmation, per the breach-notification timelines in the DPA (Section 9). Post-mortems for material incidents are published in the public changelog with the technical detail commensurate with the audience.
9. Backups + recovery
Supabase performs daily encrypted physical backups of the production database, retained for 7 days. Point-in-time recovery has been enabled since 5 October 2026, allowing the database to be restored to any moment within the trailing 7 days; before that date, recovery ran from the most recent daily backup. Recovery procedures are documented in the Business Continuity and Disaster Recovery Plan and were exercised in a tabletop review on 6 June 2026. Recovery objectives are inherited from the managed infrastructure provider and have not yet been validated by a full restoration test.
10. Audit posture (today, and where we’re going)
The current state and the roadmap:
- SOC 2 Type II: An independent CPA firm is auditing Palanor against the Security trust services criteria for the period 15 July to 15 October 2026. The report will be available to customers under NDA once issued.
- ISO 27001: Will be added to the Vanta program after SOC 2 Type II issuance. No fixed date yet.
- HIPAA / BAA: Not in scope today. Will be added when a healthcare prospect requires it.
- Sub-processor SOC 2 inheritance: Vercel, Supabase, Anthropic, Resend, ElevenLabs, OpenAI, Stripe — all SOC 2 Type II certified. Reports available from each provider directly.
11. Customer security questionnaires
We respond to CAIQ v4, SIG Lite, and custom vendor security assessments. Once the Vanta Trust Center is live (Q3 2026), the responses will be available for download under NDA from this page. Until then, please email security@palanor.com with the questionnaire and your timeline; we respond within 5 business days.
12. Contact
- Security reports: security@palanor.com
- Privacy + DSAR requests: privacy@palanor.com
- Vulnerability disclosure (machine-readable): /.well-known/security.txt
Acknowledgments
Researchers who have responsibly disclosed vulnerabilities to Palanor will be listed here with their permission. The list is empty today.
Cross-references: Privacy Policy · Data Processing Agreement · Subprocessors · Terms of Service · How we use AI.