For security reviewers
Security pack
This page sums up how Seen protects customer data, and what is not done yet. Every date, count and status here is read from our own records. Where no record exists yet, the page says so.
Produced on 8 Oct 2026.
Controls summary
We map our controls to SOC 2 and to ISO/IEC 27001:2022 Annex A, and mark each one as in place, partly in place, or not in place. This is a readiness check, not a certification. No auditor has reviewed it.
Do we hold an ISO 27001 certificate or a SOC 2 report? No, not yet.
SOC 2 (Security, Availability, Confidentiality)
- In place
- 7
- Partly in place
- 27
- Not in place
- 4
- Does not apply
- 0
38 controls mapped
ISO/IEC 27001:2022 Annex A
- In place
- 18
- Partly in place
- 52
- Not in place
- 22
- Does not apply
- 1
93 controls mapped
Where data lives
Our privacy policy says:
Your data is stored on servers in the United States.
We are now confirming the region of each place below from the provider's own console. A region is shown only after a person has read it and recorded the date.
Read so far: 0 of 8.
- Workspace database (all workspace records)Not read yet
- Platform database (accounts, plans, audit log)Not read yet
- Application servers (every request)Not read yet
- Uploaded filesNot read yet
- Outgoing emailNot read yet
- Error reportsNot read yet
- Off-site backups (encrypted)Not read yet
- Backup runner (data passes through in memory, before encryption)Not read yet
Sub-processors
Outside companies that hold or process customer data for us.
Vercel
Hosting: every request, every uploaded file, the firewall and runtime logs.
Region: see Where data lives
Data processing agreement: Published by the provider (https://vercel.com/legal/dpa)
Neon
Both databases, and their restore history.
Region: see Where data lives
Data processing agreement: Not recorded
Sentry
Error reports from our servers, and from browsers once that is turned on, with personal data removed before sending.
Region: see Where data lives
Data processing agreement: Published by the provider (https://sentry.io/legal/dpa/)
Email provider (name not recorded here)
Every email the product sends: the address, the subject and the body.
Region: see Where data lives
Data processing agreement: Not recorded
Cloudflare Turnstile
The check that a visitor is a person, on the sign-up and sign-in pages.
Region: Not read yet
Data processing agreement: Published by the provider (https://www.cloudflare.com/cloudflare-customer-dpa/)
Google
Sign-in with Google: the person's Google identity.
Used only if this sign-in option is turned on. Whether it is on is not recorded.
Region: Not read yet
Data processing agreement: Not recorded
Microsoft
Sign-in with Microsoft: the person's Microsoft identity.
Used only if this sign-in option is turned on. Whether it is on is not recorded.
Region: Not read yet
Data processing agreement: Not recorded
GitHub
Source code and automated checks, which use test data only. Once the off-site backup is set up, both databases and every file pass through its machines, in memory, before they are encrypted.
Region: Not read yet
Data processing agreement: Not recorded
Cloudflare R2
Once the off-site backup is set up: encrypted copies of both databases and every file. The provider cannot read them.
Region: see Where data lives
Data processing agreement: Published by the provider (https://www.cloudflare.com/cloudflare-customer-dpa/)
Whether we have accepted or signed each provider's agreement is not recorded yet. A link means only that the provider publishes one.
Encryption
Connections to our databases are encrypted in transit (TLS) only.
Confirmed by the account holder: a provider defaultDatabase storage is encrypted at rest, backups included.
Confirmed by the account holder: a provider defaultBrowsers are told to reach us over HTTPS only (HSTS).
Enforced26 sensitive fields have an extra layer of encryption (AES-256-GCM). National ID numbers and IBANs are among them.
Passwords are stored only as one-way hashes.
Access control
Each workspace's admins decide who has access, by role. Every page and every action checks the role.
No workspace can read another workspace's data. The application checks this, and the database enforces it too.
Our staff use separate accounts with their own roles. Every action they take in a customer workspace is written to an audit log.
Policy: Access control
Draft, not yet approvedBackups and recovery
Our databases can be restored to any moment in the last 7 days.
A daily encrypted copy kept outside the database provider is built, but it has not run yet. Until it runs, there is no copy outside the provider.
Uploaded files have no backup until that copy runs.
Last restore drill
Never run. No restore drill has been recorded yet.
Policy: Backup and recovery
Draft, not yet approvedIncident response
We sort every incident into one of 3 severity levels. For the most serious, our owner and our technical lead are called at once, at any hour.
For a personal data breach, we work to the notice window in Saudi data protection law: 72 hours from becoming aware.
Awaiting legal reviewTo report a security problem, write to info@seencrm.com. A person reads every report.
Policy: Incident response
Draft, not yet approvedPenetration testing
No outside penetration test has been performed yet. We have written its scope and rules.
Not yetThe testing firm has not been chosen yet.
Policies
Each policy has an owner. A policy that has not been approved is shown as a draft.
- Acceptable use (Seen staff)Draft, not yet approved
- Access controlDraft, not yet approved
- Backup and recoveryDraft, not yet approved
- Change managementDraft, not yet approved
- Data retentionDraft, not yet approved
- Incident responseDraft, not yet approved
- Information securityDraft, not yet approved
- Vendor managementDraft, not yet approved