← Back to Twellie

Twellie — Security Overview

Last Updated: April 19, 2026

This page describes the technical, organisational, and operational controls Twellie uses to protect your data. It supplements — and does not replace — the binding commitments in our Privacy Policy and Data Processing Addendum.

1. Infrastructure

All primary sub-processors hold SOC 2 Type II or equivalent third-party attestation.

2. Encryption

Scope Encryption
Data in transit (web, mobile, API) TLS 1.2+; HSTS one-year, preload-eligible
Data at rest (databases, file storage) AES-256 (via Supabase/AWS KMS)
Backups AES-256
Secrets (API keys, tokens) Managed via provider vaults; not stored in code
Passwords bcrypt (managed by Supabase Auth)

3. Access Control

4. Application Security

5. Secure Development

6. AI Safety

7. Network Security

8. Monitoring and Logging

9. Incident Response

10. Business Continuity and Disaster Recovery

11. Vendor Risk Management

12. Compliance Roadmap

Framework Status
GDPR / UK GDPR Continuous compliance; DPA available on request
CCPA / CPRA Continuous compliance; Do-Not-Sell portal live
U.S. state comprehensive privacy laws (CO, VA, CT, UT, TX, OR, MT, IA, TN, DE, NH, NJ, IN, NE, and counting) Continuous compliance
SOC 2 Type II Target: Q4 2026, after first SOC 2 Type I
ISO 27001 Under evaluation for 2027
PCI-DSS Not applicable — cardholder data handled solely by Stripe
HIPAA Not applicable — Twellie does not handle PHI
FedRAMP Not applicable — not a federal contractor

13. Responsible Disclosure

If you believe you have found a security vulnerability in Twellie:

We do not currently run a paid bug-bounty programme, but we may provide swag or service credits at our discretion.

14. Out of Scope for Responsible Disclosure

15. Attestations

We will publish third-party attestations here as they are completed. At time of this writing, no third-party security audit has been completed; an internal security review dated April 2026 addresses OWASP Top 10 and is reflected in the current controls.

16. Contact


Security is an ongoing practice, not a destination. We will update this page as we harden the platform; material changes are announced with the Last-Updated date at the top.

© 2026 Twellie, Inc.