Skip to content

Security & Architecture

Last updated: August 1, 2026

How Corply protects company and founder data today.

This page describes controls Corply operates today. We do not present planned controls, checklists, or provider credentials as independent assurance about Corply.

Related Documents

Data Privacy

Do you use customer data to train AI models?

Corply does not use customer data to train its own models. When a product feature invokes an AI provider, data is processed under the provider configuration and terms applicable to Corply's API account.

Which AI providers do you use?

Corply currently uses Google Vertex AI for agent features and OpenAI for embeddings. The AI client you choose to connect to Corply may process your conversation under that client's own terms.

What personal data do you store?

To form and maintain your company we store founder identity details, company information, formation and equity documents, tax and filing information, cap table data, and billing records. Access is limited to delivering and supporting the services you've requested.

Infrastructure & Security

Where is my data stored?

Application services run on Google Cloud. Structured company records are stored in managed PostgreSQL through Supabase, and canonical documents are stored in a private Google Cloud Storage bucket.

What exactly do you store?

  • Company & founder data: legal names, addresses, ownership percentages, and roles used to prepare your filings.
  • Formation documents: certificate of incorporation, bylaws, board and stockholder consents, stock purchase agreements, and 83(b) elections.
  • Cap table & equity: shares issued, option grants, and vesting schedules.
  • Payment and financial-product records: checkout status and provider references, plus account, transaction, wallet, or card data required for financial features you use.

What security measures do you have in place?

Corply's current technical controls include:

  • Transport security: HTTPS/TLS for browser, API, and MCP traffic
  • Access control: OAuth authentication, organization membership checks, and server-side authorization
  • Database isolation: row-level security policies and restricted browser write access
  • Document storage: private objects with time-limited signed download links
  • Record integrity: hashes and event records for sensitive signing and evidence workflows
  • Payment boundaries: payment and financial flows use dedicated server-side authorization and restrict browser access to sensitive values

How do you protect my legal documents?

Canonical documents are stored as private objects and downloaded through time-limited signed links. Signing and evidence workflows bind sensitive records to hashes and authorization state.

Security Reporting

Do you publish an independent security audit or penetration-test report?

Not currently. Corply will not claim an independent audit or test until a completed engagement supports that claim.

How do I report a security issue?

Email founders@corply.dev with the affected surface and enough detail for us to investigate. Do not include passwords, private keys, full payment-card data, or taxpayer identifiers.

How do you handle data breaches?

If you report a suspected incident, Corply will assess it and respond based on its scope and applicable obligations.

Your Data Control

Can I export my data?

Contact founders@corply.dev to request an export of the company records and documents currently available in your Corply account.

Can I delete my data?

You can request account or data deletion at founders@corply.dev. We will confirm what can be deleted and what must be retained for legal, security, payment, or company-record obligations.

Who can access my data?

Product access is limited by organization membership and server-side authorization. Authorized personnel and service providers may access data when needed to operate, secure, or support the service.

Data Management

How long do you retain my data?

Corply retains records while needed to provide the service and meet legal, security, payment, and company-record obligations. Contact founders@corply.dev for the current retention treatment applicable to a specific record or deletion request.

Where is my data processed?

Corply uses Google Cloud, Supabase, and the subprocessors listed below. Processing location can vary by provider and configuration; contact us if you need current location details for procurement or legal review.

Service Providers

Which core service providers do you use?

Core providers currently include the following. Contact founders@corply.dev if you need the current full list for procurement or legal review.

  • Google Cloud: application hosting, private document storage, and Vertex AI
  • Supabase: authentication and managed PostgreSQL
  • Stripe: billing and payment processing
  • OpenAI: embeddings used for product retrieval
  • Resend: transactional email delivery
  • OpenSOSData: proposed company-name searches
  • Google Analytics: website usage analytics

Resources

Where can I learn more?

For anything not covered here, reach us at founders@corply.dev, or review our Terms of Use and Privacy Policy.