Security & data handlingWhat is actually true
What is actually true
about how we handle data.
This page covers two things: how this website itself is built and who touches data you send through it, and how the engagement model already handles data-sensitive decisions. It also states plainly what we do not have yet, instead of leaving the question unanswered.
How supalabs.co is built
No backend. No database. Two named sub-processors.
No backendsupalabs.co is a static export (Next.js output: "export"). There is no server-side application code running against a database — because there is no database behind this site at all.
Hosted on CloudflareThe site is built and deployed to Cloudflare Pages on every push to our main branch, served from Cloudflare’s global edge network.
Two named sub-processors, nothing elseContact and lead forms are sent via EmailJS (a client-side email API). Call bookings go through a public Google Calendar link. Neither is bundled with anything else — there is no first-party CRM or database on this site collecting form data.
This section describes the marketing site you are reading. It does not describe engagement infrastructure — that is scoped per engagement, below.
During an engagementRead the full method →
The parts of the method that are already security decisions.
A decision log you can openEvery agent action taken during a build, its inputs, its confidence, and who approved it, rendered as a surface a compliance officer can open without asking an engineer for help.
Human approval at every irreversible stepNothing that cannot be undone happens without a person signing off first. This is a design constraint on every build, not a configurable option.
The ERP-additive covenantWe build on top of your existing systems. We do not propose replacing them, and we do not require a migration — which means we are not asking you to move your data anywhere new.
Read this before you assume otherwise
What we do not have yet.
If your procurement process runs on a checklist, better to find the gaps here than after a qualification call.
No SOC 2 or ISO 27001 — yetWe do not hold a third-party security certification today. If that is a hard requirement for your procurement process, say so on the qualification call and we will tell you honestly whether we can meet your timeline.
No templated DPA on this siteData-processing terms for an engagement are agreed per engagement, not published as a standard document here. Ask for one on the call rather than assuming either way.
No published hosting-region commitment for engagement workWhere engagement infrastructure runs (yours, ours, or a named cloud provider) depends on the engagement and is scoped during the Mapping Sprint, not fixed in advance.
Have a specific security question?
Ask it directly on the qualification call. We will give you a straight answer, including “not yet”.