Account-scoped access
Evidence, credentials, monitoring and webhook records are queried by the authenticated account identifier.

SECURITY & TRUST CENTRE
CompanyProof is in private beta. This page separates controls present in the deployed architecture from the operational, legal and assurance work still required before general availability.
No SOC 2, ISO 27001 or penetration-test badge is claimed on this site unless and until the relevant assurance has been completed and can be evidenced.
DEPLOYED CONTROLS
These are narrow implementation statements, not a claim that private beta is ready for every enterprise security review.
Evidence, credentials, monitoring and webhook records are queried by the authenticated account identifier.
CompanyProof API keys are displayed once, stored as SHA-256 hashes and can be revoked independently.
Endpoint secrets are encrypted with AES-GCM at rest and are never displayed again after creation.
Webhook payloads use HMAC-SHA256 signatures, replay identifiers, bounded retries, redirect rejection and delivery history.
Company-data and Stripe credentials are read only by server-side code and are never sent to the browser.
Public data workflows and sensitive account actions have persistent rate limits, payload limits and strict input validation.
A proof, its claims, decision events and usage event are committed as one database batch or rolled back together.
Credential, webhook, monitoring and billing actions are recorded with actor, time and a shortened network hash.
Responses set anti-framing, content-type, referrer, permissions, HSTS and sensitive-page cache controls.
Billing entitlements change only after Stripe signature verification and replay-safe event processing.
DATA HANDLING MODEL
A verification request contains a company identity and the claims or answer to verify. Customer and service credentials remain server-side. The proof and evidence record are stored under the authenticated account.
Sends company identity and claims using a revocable CompanyProof key.
Validates limits, resolves the entity and obtains the selected company evidence.
Atomically stores the proof, claim events, source context and monitoring state.
REQUIRED BEFORE GENERAL AVAILABILITY
These controls are requirements, not completed-certification claims. Enterprise production contracts should not begin until the applicable controls have been implemented and verified.
Activate WorkOS Google, Microsoft, Apple, passkey and SSO sign-in and verify the custom-domain callback configuration.
Add invitations, role-based permissions, owner transfer and administrative separation of duties.
Document backup coverage, run restoration exercises and evidence recovery objectives.
Route structured security events to alerting and define ownership for anomalous activity.
Move from baseline CSP navigation controls to nonce- or hash-based script restrictions after analytics integrations are final.
Contractual retention controls and verified deletion workflows.
Documented escalation, notification, recovery and post-incident review.
Complete a penetration test and claim certifications only after the applicable assessment is formally complete.
Approve the DPA, subprocessor register, service schedule and security architecture summary.
PROCUREMENT DOCUMENTATION
START THE SECURITY REVIEW EARLY