Already with Seen? Log in

For security reviewers

Security pack

This page sums up how Seen protects customer data, and what is not done yet. Every date, count and status here is read from our own records. Where no record exists yet, the page says so.

Produced on 8 Oct 2026.

Controls summary

We map our controls to SOC 2 and to ISO/IEC 27001:2022 Annex A, and mark each one as in place, partly in place, or not in place. This is a readiness check, not a certification. No auditor has reviewed it.

Do we hold an ISO 27001 certificate or a SOC 2 report? No, not yet.

SOC 2 (Security, Availability, Confidentiality)

In place
7
Partly in place
27
Not in place
4
Does not apply
0

38 controls mapped

ISO/IEC 27001:2022 Annex A

In place
18
Partly in place
52
Not in place
22
Does not apply
1

93 controls mapped

Where data lives

Our privacy policy says:

Your data is stored on servers in the United States.

We are now confirming the region of each place below from the provider's own console. A region is shown only after a person has read it and recorded the date.

Read so far: 0 of 8.

  • Workspace database (all workspace records)Not read yet
  • Platform database (accounts, plans, audit log)Not read yet
  • Application servers (every request)Not read yet
  • Uploaded filesNot read yet
  • Outgoing emailNot read yet
  • Error reportsNot read yet
  • Off-site backups (encrypted)Not read yet
  • Backup runner (data passes through in memory, before encryption)Not read yet

Sub-processors

Outside companies that hold or process customer data for us.

  • Vercel

    Hosting: every request, every uploaded file, the firewall and runtime logs.

    Region: see Where data lives

    Data processing agreement: Published by the provider

  • Neon

    Both databases, and their restore history.

    Region: see Where data lives

    Data processing agreement: Not recorded

  • Sentry

    Error reports from our servers, and from browsers once that is turned on, with personal data removed before sending.

    Region: see Where data lives

    Data processing agreement: Published by the provider

  • Email provider (name not recorded here)

    Every email the product sends: the address, the subject and the body.

    Region: see Where data lives

    Data processing agreement: Not recorded

  • Cloudflare Turnstile

    The check that a visitor is a person, on the sign-up and sign-in pages.

    Region: Not read yet

    Data processing agreement: Published by the provider

  • Google

    Sign-in with Google: the person's Google identity.

    Used only if this sign-in option is turned on. Whether it is on is not recorded.

    Region: Not read yet

    Data processing agreement: Not recorded

  • Microsoft

    Sign-in with Microsoft: the person's Microsoft identity.

    Used only if this sign-in option is turned on. Whether it is on is not recorded.

    Region: Not read yet

    Data processing agreement: Not recorded

  • GitHub

    Source code and automated checks, which use test data only. Once the off-site backup is set up, both databases and every file pass through its machines, in memory, before they are encrypted.

    Region: Not read yet

    Data processing agreement: Not recorded

  • Cloudflare R2

    Once the off-site backup is set up: encrypted copies of both databases and every file. The provider cannot read them.

    Region: see Where data lives

    Data processing agreement: Published by the provider

Whether we have accepted or signed each provider's agreement is not recorded yet. A link means only that the provider publishes one.

Encryption

Connections to our databases are encrypted in transit (TLS) only.

Confirmed by the account holder: a provider default

Database storage is encrypted at rest, backups included.

Confirmed by the account holder: a provider default

Browsers are told to reach us over HTTPS only (HSTS).

Enforced

26 sensitive fields have an extra layer of encryption (AES-256-GCM). National ID numbers and IBANs are among them.

Passwords are stored only as one-way hashes.

Access control

Each workspace's admins decide who has access, by role. Every page and every action checks the role.

No workspace can read another workspace's data. The application checks this, and the database enforces it too.

Our staff use separate accounts with their own roles. Every action they take in a customer workspace is written to an audit log.

Policy: Access control

Draft, not yet approved

Backups and recovery

Our databases can be restored to any moment in the last 7 days.

A daily encrypted copy kept outside the database provider is built, but it has not run yet. Until it runs, there is no copy outside the provider.

Uploaded files have no backup until that copy runs.

Last restore drill

Never run. No restore drill has been recorded yet.

Policy: Backup and recovery

Draft, not yet approved

Incident response

We sort every incident into one of 3 severity levels. For the most serious, our owner and our technical lead are called at once, at any hour.

For a personal data breach, we work to the notice window in Saudi data protection law: 72 hours from becoming aware.

Awaiting legal review

To report a security problem, write to info@seencrm.com. A person reads every report.

Policy: Incident response

Draft, not yet approved

Penetration testing

No outside penetration test has been performed yet. We have written its scope and rules.

Not yet

The testing firm has not been chosen yet.

Policies

Each policy has an owner. A policy that has not been approved is shown as a draft.

  • Acceptable use (Seen staff)Draft, not yet approved
  • Access controlDraft, not yet approved
  • Backup and recoveryDraft, not yet approved
  • Change managementDraft, not yet approved
  • Data retentionDraft, not yet approved
  • Incident responseDraft, not yet approved
  • Information securityDraft, not yet approved
  • Vendor managementDraft, not yet approved