Security & compliance

How Sales Commander protects your data

Hosted in the AWS London region, with tenant isolation enforced in the database.

Opens Julian Reading's LinkedIn, where you can message him.

Infrastructure

Hosted in London.

The Sales Commander database runs on Supabase in Amazon Web Services eu-west-2, the London region, and its backups are kept in the same region. The web application is hosted on AWS Amplify, and the live call listener on AWS, both in eu-west-2.

Providers that receive customer data

Some features send data to specialist providers, some of which process it outside the United Kingdom:

  • Anthropic: the Commander's analysis and coaching (deal text, call transcript text and account research, with email addresses, phone numbers and money figures removed first by default)
  • ElevenLabs: voice features: dictation and reading coaching aloud
  • Firecrawl, Apollo and People Data Labs: public company and contact research, when those features are used
  • Resend: sign-in, invitation and notification emails
  • Sentry: error reports from the application, in its EU region
  • Cloudflare: Turnstile protection on the sign-in pages

Anthropic does not train models on this data.

Security controls

Protection at every layer

Security is built into Sales Commander's architecture, not bolted on.

Shared responsibility

What our infrastructure providers cover. What we cover.

Under the AWS Shared Responsibility Model, compliance is a partnership.

AWS and Supabase responsibility (infrastructure)

  • Physical data centre security
  • Hardware and network infrastructure
  • Power, cooling, and environmental controls
  • Hypervisor and virtualisation layer
  • Storage and compute hardware encryption
  • Global network and DDoS infrastructure

Sales Commander responsibility (application)

  • Application code and security
  • Customer data encryption and isolation
  • Identity, authentication, and access control
  • Audit logging and monitoring
  • Incident detection and response
  • GDPR and UK data protection compliance

Compliance

Where we are today

We are transparent about where we are in our compliance journey.

CertificationScopeStatusNotes
AWS SOC 2 Type IIAWS infrastructureHeld by AWSReport available from AWS Artifact
AWS ISO 27001AWS infrastructureHeld by AWSCertificate available from AWS Artifact
SOC 2, ISO 27001 or Cyber Essentials of our ownSales CommanderNot yet heldWe do not claim any certification we do not hold

Documentation

Security resources

Documentation to support your procurement and due diligence process.

Have a security question?

We respond to all security enquiries and questionnaires. Contact our team directly.

Opens Julian Reading's LinkedIn, where you can message him.