Encryption in transit & at rest
All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 by the managed database provider.
This page is maintained by PatrolOS to answer common security and privacy questions about our platform. It describes controls that are enabled today; it is not an independent certification.
All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 by the managed database provider.
Row-level security scopes every read and write to the signed-in user's organization and role.
Supabase-managed auth with email + OAuth. Administrators can require MFA per organization.
Hosted on Cloudflare and Supabase infrastructure with automatic backups and 24/7 monitoring.
Sensitive actions (role changes, data exports, checkpoint edits) are written to an append-only audit log.
We investigate reported security issues within one business day. Report to angel18almanza@gmail.com.
Third parties that process customer data on our behalf.
Data subject requests (access, deletion, portability) can be submitted to angel18almanza@gmail.com. We respond within 30 days as required by GDPR and CCPA.
PatrolOS holds no third-party security certification today. We do not claim SOC 2, ISO 27001, HIPAA, or PCI compliance, and we will only say otherwise here once an independent report exists. What we do describe on this page are the controls that are actually live in the product.
This page is maintained by PatrolOS and is not independent verification. Security questionnaires are answered on request — see our legal documents for data processing terms.
Please email angel18almanza@gmail.com with a description of the issue and reproduction steps. We acknowledge reports within one business day.
Enterprise customers can request a signed Data Processing Agreement, complete a security questionnaire, or schedule a review call with our team.
Contact our team