Security & compliance
How Sales Commander protects your data
Hosted in the AWS London region, with tenant isolation enforced in the database.
Opens Julian Reading's LinkedIn, where you can message him.
Infrastructure
Hosted in London.
The Sales Commander database runs on Supabase in Amazon Web Services eu-west-2, the London region, and its backups are kept in the same region. The web application is hosted on AWS Amplify, and the live call listener on AWS, both in eu-west-2.
Providers that receive customer data
Some features send data to specialist providers, some of which process it outside the United Kingdom:
- Anthropic: the Commander's analysis and coaching (deal text, call transcript text and account research, with email addresses, phone numbers and money figures removed first by default)
- ElevenLabs: voice features: dictation and reading coaching aloud
- Firecrawl, Apollo and People Data Labs: public company and contact research, when those features are used
- Resend: sign-in, invitation and notification emails
- Sentry: error reports from the application, in its EU region
- Cloudflare: Turnstile protection on the sign-in pages
Anthropic does not train models on this data.
Security controls
Protection at every layer
Security is built into Sales Commander's architecture, not bolted on.
Tenant isolation
Every record belongs to one organisation. Row-level security in the database enforces that boundary for every signed-in user, so isolation does not depend on the interface.
Encryption
All traffic to the application and its database API travels over HTTPS, and direct connections to the database must use SSL. Stored data is encrypted at rest by the database platform, and CRM and Zoom credentials are additionally encrypted with a managed key that only server-side functions can use.
Sign-in
Accounts are created by invitation only. Passwords must be at least 12 characters and are checked against known breached passwords, and sign-in is protected against automated attempts by Cloudflare Turnstile.
Sessions and access
Sessions use access tokens that expire after one hour, with refresh-token rotation. What each person can see and do is set by their role and checked on the server and in the database.
Audit logging
Security and administrative events are recorded in an audit log with who acted, when and on what, and kept for 12 months.
Backups and deletion
The database has point-in-time recovery with a 14-day window, kept in the London region. Customer data is deleted within 30 days of a verified deletion request. When a contract ends, an export is offered first.
Shared responsibility
What our infrastructure providers cover. What we cover.
Under the AWS Shared Responsibility Model, compliance is a partnership.
AWS and Supabase responsibility (infrastructure)
- Physical data centre security
- Hardware and network infrastructure
- Power, cooling, and environmental controls
- Hypervisor and virtualisation layer
- Storage and compute hardware encryption
- Global network and DDoS infrastructure
Sales Commander responsibility (application)
- Application code and security
- Customer data encryption and isolation
- Identity, authentication, and access control
- Audit logging and monitoring
- Incident detection and response
- GDPR and UK data protection compliance
Compliance
Where we are today
We are transparent about where we are in our compliance journey.
| Certification | Scope | Status | Notes |
|---|---|---|---|
| AWS SOC 2 Type II | AWS infrastructure | Held by AWS | Report available from AWS Artifact |
| AWS ISO 27001 | AWS infrastructure | Held by AWS | Certificate available from AWS Artifact |
| SOC 2, ISO 27001 or Cyber Essentials of our own | Sales Commander | Not yet held | We do not claim any certification we do not hold |
Documentation
Security resources
Documentation to support your procurement and due diligence process.
Sub-processor statement
Which third parties receive your data when you use the Commander and its research features, what each receives, and how long it keeps it. Available on request. Customers also see their own version, built from their settings, on the Admin page.
AWS compliance reports
SOC 2 Type II, ISO 27001, and other AWS certifications covering the AWS infrastructure layer. Available via AWS Artifact.
Have a security question?
We respond to all security enquiries and questionnaires. Contact our team directly.
Opens Julian Reading's LinkedIn, where you can message him.