Skip to content

Demo content — this page shows example security and trust information for the Public Surface template. Badges, compliance status and sub-processors below are fictional. Replace them with your own before publishing.

SECURITY & TRUST

Security you can verify

How Public Surface protects customer data, and what to expect when your security team reviews us. This page is example content for the template — replace every claim with your own posture before you publish.

PRINCIPLES

How we think about security

Encrypted by default

TLS 1.3 in transit and AES-256 at rest, on every plan, with no configuration required.

Least-privilege access

Role-based permissions and scoped API keys throughout the product, not just at the account level.

Independently reviewed

Built to withstand the security questionnaires and audits that come with selling upmarket.

Transparent by design

Status, incidents and security-relevant changes are published, not handled behind closed doors.

ENCRYPTION & DATA PROTECTION

Data protection

IN TRANSIT

TLS 1.3 for all client and internal traffic, with modern cipher suites enforced everywhere.

AT REST

AES-256 encryption for databases, object storage and backups.

KEY MANAGEMENT

Managed encryption keys with periodic rotation; customer-managed keys available on Enterprise (example).

DATA RETENTION

Configurable retention windows, with deletion on request completed within 30 days (example).

AUTHENTICATION & ACCESS

Authentication and access controls

SINGLE SIGN-ON

SAML 2.0 and OIDC, enforceable per workspace so every login goes through your identity provider.

DIRECTORY SYNC

SCIM provisioning for Okta, Entra ID and Google Workspace keeps membership in sync automatically.

ROLE-BASED ACCESS

Owner, Admin, Member and Read-only roles are available on every plan, not gated to Enterprise.

MULTI-FACTOR AUTH

Required for all workspace owners and admins; optional and enforceable for everyone else.

AUDIT LOGS

Exportable log of authentication events and permission changes (example).

INFRASTRUCTURE & AVAILABILITY

Infrastructure and availability

HOSTING

Multi-region cloud infrastructure with automated failover between availability zones (example).

UPTIME

99.95% uptime target, with status and incidents published live on our status page (example).

BACKUPS

Automated daily backups with point-in-time recovery, retained on a rolling window (example).

DATA RESIDENCY

Choose US or EU storage at the project level; data does not leave the selected region.

VULNERABILITY REPORTING

Responsible disclosure

If you believe you’ve found a security vulnerability in Public Surface, we want to hear about it. Report it privately and we’ll work with you to understand and resolve it before any public disclosure.

01 — REPORT

Send us the details

Email a clear description, steps to reproduce, and any proof-of-concept to our security address.

02 — ACKNOWLEDGE

We confirm receipt

Expect an acknowledgement within 2 business days, with an initial assessment to follow (example).

03 — RESOLVE

We fix and disclose

We patch confirmed issues and coordinate disclosure timing with you before going public.

security@publicsurface.dev

COMPLIANCE

Compliance posture (example)

The table below is an example compliance posture for this template. Replace it with your organization’s real certifications, audit dates and evidence links.

SOC 2 Type II

Readiness

Audit engagement underway — target completion Q4 2026 (example).

GDPR

Compliant

Data processing addendum available on request (example).

CCPA

Compliant

California privacy rights supported for all customers (example).

ISO 27001

Planned

Certification planned for 2027 as the company scales (example).

SUB-PROCESSORS

Sub-processors (example)

Third parties we use to help operate Public Surface. The provider names below are fictional examples for this template — replace this table with your own vendor list.

PROVIDER

PURPOSE

DATA PROCESSED

REGION

DPA

Cloudline Infrastructure

Cloud hosting & compute

Account data, application logs, telemetry

Global

View

Meridian CDN

Content delivery & edge caching

IP address, request metadata

Global

View

Watchtower Monitoring

Error tracking & uptime monitoring

Stack traces, request metadata

US

View

Beacon Analytics

Product usage analytics

Usage events, device metadata

US

View

Signalwire Mail

Transactional email delivery

Email address, message content

US

View

Paylight

Payment processing & billing

Billing contact, payment metadata

US

View

Relay Support

Customer support platform

Support tickets, account email

EU

View

Ledger Books

Accounting & invoicing

Billing records, company details

EU

View

LEGAL

Privacy and legal resources

Privacy Policy

Connect your legal page

Terms of Service

Connect your legal page

Data Processing Agreement (DPA)

Connect your legal page

Sub-processor list

CONTACT

Talk to security

Security questionnaires, procurement reviews, or a vulnerability report — reach the team directly and we’ll get back to you.

Create a free website with Framer, the website builder loved by startups, designers and agencies.