Security

Your customer conversations are the most sensitive data you have. Here’s how we treat them.

Resonant IQ is a customer evidence layer — it ingests your customer conversations and account activity to show you why accounts are healthy or slipping, with receipts. We built the security architecture before we onboarded our first customer, because a product whose entire value is trustworthy evidence has to start by being trustworthy with the evidence.

This page describes what is actually built and running today. No aspirational language; where something is planned rather than shipped, we say so.

Tenant isolation

Every customer’s data lives in a logically isolated tenant, enforced in depth:


Access control


Audit logging


Data handling


AI and your data

Resonant IQ uses large language models to score and detect signals in conversations.


Infrastructure & subprocessors

We run on a small, deliberate set of providers:

ProviderRole
VercelApplication hosting
SupabaseDatabase (Postgres), at-rest encryption, backups
AnthropicAI conversation scoring
Voyage AIEmbeddings (semantic search)
StripeBilling (we never store payment credentials)
InngestBackground job processing
SentryError monitoring (PII scrubbed before transmission)
ResendTransactional email
Help ScoutCustomer support
Google WorkspaceInternal email & docs

Compliance posture — where we actually stand

We are pre-launch and do not yet hold a SOC 2 report. What we have instead, and have had since early 2026, is a running internal controls program: security-relevant work is mapped to SOC 2 Trust Services Criteria (CC6, CC7, C1) in a living controls inventory maintained in our codebase, with code references and implementation status updated in the same pull request that ships each control. Tenant isolation, access control, audit logging, and backup/recovery controls described on this page are implemented and verifiable — not planned.

We also support GDPR data-subject obligations: full tenant data export on request, and deletion as described above.

A formal SOC 2 audit is planned once we have production customers; the controls program above exists so that audit is a verification exercise, not a remediation project. Our full security documentation is available under NDA, and we’re glad to complete your security questionnaire.


Contact

Security questions or vulnerability reports: security@resonantiq.app

Privacy Policy · Terms of Service · Back to home