Security
How we protect the customs entry data you upload, and which providers process it. Last checked against our code, production configuration, and provider documentation on September 23, 2026.
Encryption
Data at rest is encrypted with AES-256 by our database and file storage provider, Supabase. Data in transit is encrypted with TLS 1.2 or higher between your browser and our servers, and browsers are instructed to connect over HTTPS only (HTTP Strict Transport Security).
Tenant Isolation
Customer tables are protected by Row-Level Security (RLS) policies scoped to your organization, so the database enforces organization boundaries in addition to the checks in our application code.
Import entries, audit runs, and recovery opportunities chain their RLS policies through the importer relationship to your organization, rather than trusting a client-supplied organization ID directly.
Access Controls & Authentication
Every protected route calls Supabase's session-verified getUser() — never a cookie-presence check — and our edge middleware enforces authentication on every protected route prefix before a request reaches application code.
Role-based access (Admin, Analyst, Read Only) governs who on your team can upload data, run audits, change settings, or invite others.
Uploaded files are kept in private storage buckets. Downloads use signed links that expire: one hour for stored documents, and seven days for generated audit-response packages.
Platform Hardening
CSV uploads and team invitations use input validation and rate limiting.
Stripe webhook events are verified using Stripe-signed event validation before processing.
Standard security headers are set on every response: X-Frame-Options, X-Content-Type-Options, a strict Referrer-Policy, and a Permissions-Policy that disables camera, microphone, and geolocation access.
Data Retention & Deletion
Account deletion is a manual, request-based process — email privacy@dutyrecover.ai to request it. We respond without undue delay and within one month where data protection law applies. Cancelling a paid plan does not delete any data.
Self-service account deletion is not yet built. Retention periods are set out in our Privacy Policy, which is currently a draft.
Subprocessors
We use the following providers to deliver the service:
• Supabase — database hosting, authentication, file storage. Supabase holds a SOC 2 Type 2 attestation (Supabase's, not ours).
• Stripe — payment processing through Stripe-hosted Checkout, so card details are entered on Stripe's pages and never reach our servers. Stripe is certified as a PCI DSS Service Provider Level 1 (Stripe's certification, not ours).
• Vercel — application hosting, edge network, web analytics, and performance monitoring. Vercel holds a SOC 2 Type 2 attestation (Vercel's, not ours).
• Resend — transactional email delivery.
• Sentry — error monitoring and, when an error occurs, a masked session replay. Cookies, authorization headers, request bodies, IP addresses, and URL query strings are removed before reports are sent; session replays mask on-screen text and form inputs and block images and media.
• Upstash — rate limiting, using IP addresses and account or organization identifiers. Requests are routed to the nearest of several regions worldwide, including the United States, the UK and Australia.
• Anthropic — AI-assisted classification, drafting, and CBP Form 28 extraction (Claude). Anthropic receives the text inputs of the AI feature you use — product details, entry details, organization and importer names, notes, case details, and file names — and the complete PDF when you upload a CBP Form 28 for extraction. The contents of other Document Vault files are not sent. Anthropic's commercial terms do not permit it to train its models on this content. It deletes API inputs and outputs within 30 days by default, but may keep inputs and outputs flagged under its usage policy for up to 2 years. We have not arranged zero data retention with Anthropic.
• Google — our business email (Google Workspace), for messages sent to our @dutyrecover.ai addresses.
DutyRecoverAI does not hold a SOC 2 or other third-party security certification of its own. The certifications above belong to our providers, not to us.
Data Processing Agreements
Personal data in the customs records you upload is processed under the data processing terms in section 8 of our Terms of Service, which are currently a draft. Questions: privacy@dutyrecover.ai.
Questions
To report a vulnerability or ask a security question, contact security@dutyrecover.ai. For privacy questions, privacy@dutyrecover.ai; for general support, support@dutyrecover.ai.