Encryption in transit & at rest
All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 by the managed database provider.
This page is maintained by PatrolOS to answer common security and privacy questions about our platform. It describes controls that are enabled today; it is not an independent certification.
All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 by the managed database provider.
Row-level security scopes every read and write to the signed-in user's organization and role.
Supabase-managed auth with email + OAuth. Administrators can require MFA per organization.
Hosted on Cloudflare and Supabase infrastructure with automatic backups and 24/7 monitoring.
Sensitive actions (role changes, data exports, checkpoint edits) are written to an append-only audit log.
We investigate reported security issues within one business day. Report to security@patrolos.app.
Third parties that process customer data on our behalf.
Data subject requests (access, deletion, portability) can be submitted to privacy@patrolos.app. We respond within 30 days as required by GDPR and CCPA.
Where we are today and what is next. This is our current posture, not an independent certification.
Please email security@patrolos.app with a description of the issue and reproduction steps. We acknowledge reports within one business day.
Enterprise customers can request a signed Data Processing Agreement, complete a security questionnaire, or schedule a review call with our team.
Contact our team