Trust
Security
Sumptus handles expense records, receipts, and client confirmations — sensitive data that our customers rely on for audits. Here is how we protect it.
Honesty note. State only what you actually do. Update the specifics below to match your real controls, and remove any claim you cannot yet stand behind (for example, don’t list SOC 2 until you hold it).
Data protection
- Encryption in transit โ all traffic is served over TLS.
- Encryption at rest โ data and receipt images are encrypted at rest by our infrastructure provider.
- Managed infrastructure โ the platform runs on Supabase/Postgres with row-level security enforcing that each organization sees only its own data.
Access control
- Role-based access within each company (employee, manager, finance, admin).
- Row-level security policies enforced at the database, not just the app layer.
- Least-privilege access to production systems by our team.
Client verification integrity
Verification requests are single-use and time-limited. Responses are recorded with a timestamp and cannot be altered after the fact, producing a tamper-evident audit trail.
Payments
Card payments are handled by our PCI-compliant payment processor. Sumptus never stores full card numbers on its own servers.
Reporting a vulnerability
If you believe you’ve found a security issue, please email dcharles@sumptus.co with details. We appreciate responsible disclosure and will acknowledge your report promptly.
© 2026 Sumptus Technologies LLC