Security at Enrichabl: How We Protect Your Data
TL;DR
Enrichabl encrypts customer data at rest using AES-256 and in transit using TLS 1.3. BYOK API keys are protected with envelope encryption backed by a managed Key Management Service. Authentication is handled by Clerk, infrastructure runs on Railway behind Cloudflare, and we operate a responsible vulnerability disclosure program at security@enrichabl.com. We are aligned with GDPR and CCPA and are working toward SOC 2 Type II.
Encryption at Rest
AES-256
All customer data - including account records, uploaded CSVs, and enrichment results - is encrypted at rest using AES-256 with managed-key infrastructure. Database volumes and object storage are encrypted by default.
Encryption in Transit
TLS 1.3
All connections to https://enrichabl.com and our APIs use TLS 1.3 with modern cipher suites. HTTP traffic is automatically redirected to HTTPS, and we enforce HSTS at the edge.
API Key Protection (BYOK)
Envelope Encryption with KMS
Third-party API keys you connect (BYOK) are protected with envelope encryption: each key is encrypted with a unique data-encryption key (DEK), and each DEK is wrapped by a key-encryption key (KEK) held in a managed Key Management Service (KMS). Plaintext keys are only materialized in memory at the moment of an outbound provider call and are never logged.
You can rotate or revoke any provider key from your account settings at any time.
Authentication
Clerk Identity Platform
Authentication, session management, and password storage are handled by Clerk. Passwords are hashed with industry-standard algorithms, sessions are bound to secure, HttpOnly cookies, and multi-factor authentication is available on all accounts.
Infrastructure
Railway + Cloudflare Edge
Application workloads run on Railway in isolated containers with private networking between services. Public traffic terminates at Cloudflare's global edge, which provides DDoS protection, WAF rules, bot mitigation, and CDN caching for static assets. Production secrets are stored in environment-scoped vaults and never committed to source control.
Backups and Disaster Recovery
Production databases are backed up on a daily schedule with point-in-time recovery available. Backups are encrypted at rest and stored in geographically separate infrastructure. We periodically test restore procedures to verify recoverability.
Vulnerability Disclosure
Report a Security Issue
If you believe you have found a security vulnerability in Enrichabl, please email security@enrichabl.com. Include a clear description, reproduction steps, and any relevant proof-of-concept material. We will acknowledge your report within two business days.
Responsible Disclosure Policy
We are committed to working with security researchers in good faith. If you follow the guidelines below, we will not pursue legal action against you for your research:
- Make a good-faith effort to avoid privacy violations, data destruction, and service interruption.
- Only interact with accounts you own or for which you have explicit permission from the owner.
- Do not exploit the vulnerability beyond what is necessary to demonstrate it.
- Report the issue to security@enrichabl.com and give us reasonable time to remediate before public disclosure.
- Do not perform automated scanning that degrades the Service for other users.
Compliance Posture
GDPR & CCPA Aligned, SOC 2 Roadmap
Enrichabl is designed and operated to align with the GDPR and CCPA. See our Privacy Policy for details on data subject rights, sub-processors, and international transfers. We are actively working toward SOC 2 Type II attestation; reach out to security@enrichabl.com for our latest compliance status.
Built for Teams That Take Data Seriously
Encryption everywhere, BYOK by default, and a transparent disclosure policy. Try Enrichabl with confidence.
Create Free Account