Security & privacy at PatrolOS

This page is maintained by PatrolOS to answer common security and privacy questions about our platform. It describes controls that are enabled today; it is not an independent certification.

Encryption in transit & at rest

All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 by the managed database provider.

Role-based access control

Row-level security scopes every read and write to the signed-in user's organization and role.

Least-privilege authentication

Supabase-managed auth with email + OAuth. Administrators can require MFA per organization.

Managed, monitored infrastructure

Hosted on Cloudflare and Supabase infrastructure with automatic backups and 24/7 monitoring.

Audit logging

Sensitive actions (role changes, data exports, checkpoint edits) are written to an append-only audit log.

Incident response

We investigate reported security issues within one business day. Report to security@patrolos.app.

Subprocessors

Third parties that process customer data on our behalf.

  • SupabaseDatabase, authentication, storage
  • CloudflareApplication hosting and CDN
  • Lovable AI GatewayAI model inference for Copilot
  • ResendTransactional email

Data handling

  • • Customer data is scoped to your organization via row-level security.
  • • Photos, video, and voice recordings are stored in encrypted object storage.
  • • Data is retained for the life of your subscription. On request we delete within 30 days.
  • • You can export your data at any time from Settings → Billing.

Privacy requests

Data subject requests (access, deletion, portability) can be submitted to privacy@patrolos.app. We respond within 30 days as required by GDPR and CCPA.

Compliance roadmap

Where we are today and what is next. This is our current posture, not an independent certification.

  • SOC 2 controls implemented
    Access control, encryption, audit logging, and backup procedures live today.
  • SOC 2 Type II audit — in progress
    Observation window under way with an independent auditor. Report available under NDA on completion.
  • HIPAA-ready deployment — planned
    BAA available for healthcare campus customers on the Enterprise plan.

Reporting a vulnerability

Please email security@patrolos.app with a description of the issue and reproduction steps. We acknowledge reports within one business day.

Need a DPA or security questionnaire?

Enterprise customers can request a signed Data Processing Agreement, complete a security questionnaire, or schedule a review call with our team.

Contact our team