Security at Enrichabl: How We Protect Your Data

TL;DR

Enrichabl encrypts customer data at rest using AES-256 and in transit using TLS 1.3. BYOK API keys are protected with envelope encryption backed by a managed Key Management Service. Authentication is handled by Clerk, infrastructure runs on Railway behind Cloudflare, and we operate a responsible vulnerability disclosure program at security@enrichabl.com. We are aligned with GDPR and CCPA and are working toward SOC 2 Type II.

Encryption at Rest

AES-256

All customer data - including account records, uploaded CSVs, and enrichment results - is encrypted at rest using AES-256 with managed-key infrastructure. Database volumes and object storage are encrypted by default.

Encryption in Transit

TLS 1.3

All connections to https://enrichabl.com and our APIs use TLS 1.3 with modern cipher suites. HTTP traffic is automatically redirected to HTTPS, and we enforce HSTS at the edge.

API Key Protection (BYOK)

Envelope Encryption with KMS

Third-party API keys you connect (BYOK) are protected with envelope encryption: each key is encrypted with a unique data-encryption key (DEK), and each DEK is wrapped by a key-encryption key (KEK) held in a managed Key Management Service (KMS). Plaintext keys are only materialized in memory at the moment of an outbound provider call and are never logged.

You can rotate or revoke any provider key from your account settings at any time.

Authentication

Clerk Identity Platform

Authentication, session management, and password storage are handled by Clerk. Passwords are hashed with industry-standard algorithms, sessions are bound to secure, HttpOnly cookies, and multi-factor authentication is available on all accounts.

Infrastructure

Railway + Cloudflare Edge

Application workloads run on Railway in isolated containers with private networking between services. Public traffic terminates at Cloudflare's global edge, which provides DDoS protection, WAF rules, bot mitigation, and CDN caching for static assets. Production secrets are stored in environment-scoped vaults and never committed to source control.

Backups and Disaster Recovery

Production databases are backed up on a daily schedule with point-in-time recovery available. Backups are encrypted at rest and stored in geographically separate infrastructure. We periodically test restore procedures to verify recoverability.

Vulnerability Disclosure

Report a Security Issue

If you believe you have found a security vulnerability in Enrichabl, please email security@enrichabl.com. Include a clear description, reproduction steps, and any relevant proof-of-concept material. We will acknowledge your report within two business days.

Responsible Disclosure Policy

We are committed to working with security researchers in good faith. If you follow the guidelines below, we will not pursue legal action against you for your research:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service interruption.
  • Only interact with accounts you own or for which you have explicit permission from the owner.
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it.
  • Report the issue to security@enrichabl.com and give us reasonable time to remediate before public disclosure.
  • Do not perform automated scanning that degrades the Service for other users.

Compliance Posture

GDPR & CCPA Aligned, SOC 2 Roadmap

Enrichabl is designed and operated to align with the GDPR and CCPA. See our Privacy Policy for details on data subject rights, sub-processors, and international transfers. We are actively working toward SOC 2 Type II attestation; reach out to security@enrichabl.com for our latest compliance status.

Built for Teams That Take Data Seriously

Encryption everywhere, BYOK by default, and a transparent disclosure policy. Try Enrichabl with confidence.

Create Free Account