Trust Center
The short version procurement needs: how we protect your data, who processes it, and where we stand on compliance. For the long form, see Security & Sovereign Ethics.
Row-level security on every table — no customer can read another's data. Verified in tests.
TLS 1.2+ in transit, encrypted at rest. HSTS on all origins.
We never sell personal data and show no ads. Your diagnoses are yours.
Voice intake is transcribed in your browser — raw audio never leaves your device.
| Vendor | Purpose | Data |
|---|---|---|
| Supabase | Database & authentication | Account, brand, diagnosis data |
| Stripe | Billing & payments | Billing identity (no card numbers stored by Begrasp) |
| Modal | Engine runtime | Transient — reads intake, writes diagnosis |
| Resend | Transactional email | Email address, message content |
| Vercel | App & site hosting / CDN | Request metadata |
Each subprocessor operates under a data-processing agreement. The authoritative, dated list lives on the DPA page.
Security issue: security@begrasp.com · Privacy request: privacy@begrasp.com · Everything else: hello@begrasp.com.