Security
Tier1/AI, operated by INS Digital Intelligence LLC
Effective: July 24, 2026
Last updated: July 24, 2026
OVERVIEW
Tier1/AI handles communications and capital markets communications data for capital markets clients. That means investor lists, CRM notes, campaign copy, engagement metrics, and OAuth-connected mailboxes. We treat this data with a security posture proportional to its sensitivity.
This page describes what we do to protect Client data, how we handle security incidents, and how security researchers can report vulnerabilities to us.
1. INFRASTRUCTURE AND HOSTING
Tier1/AI runs on:
- Supabase - database (PostgreSQL), authentication, storage, and edge functions
- Vercel - application and marketing site hosting
- Mailgun - email delivery
Each provider maintains its own security certifications and audit programs. See our Privacy Policy Section 9 for the full subprocessor list.
2. ENCRYPTION
2.1 Data in transit.
All connections to Tier1/AI use TLS 1.2 or higher. Marketing site, platform, API endpoints, and edge functions are served over HTTPS exclusively.
2.2 Data at rest.
Stored credentials - OAuth tokens, service keys, and API secrets - are encrypted at rest by Supabase Vault. The database itself is encrypted at the storage layer by Supabase.
3. ACCESS CONTROL
3.1 Row Level Security.
The database enforces Row Level Security (RLS) policies on all Client-scoped tables. Client data is isolated per organization. RLS is validated by our schema drift check on every deploy.
3.2 Service-role key isolation.
The Supabase service-role key, which bypasses RLS, is used only by server-side edge functions. It is never exposed to client-side code and never included in browser bundles.
3.3 Principle of least privilege.
Internal access to production data is limited to those with a specific operational need. Admin actions are logged.
3.4 Multi-factor authentication.
MFA is available for administrator accounts.
4. MONITORING
We monitor the Service using:
- Sentry - application error monitoring and diagnostics
- Supabase - authentication events, RLS policy violations, and edge function invocations
Anomalous patterns trigger review.
5. DEPENDENCY MANAGEMENT
We keep application dependencies and platform components up to date. Security-relevant updates are prioritized. Dependency vulnerabilities identified by our tooling are triaged on receipt.
6. BACKUPS
Backup snapshots are maintained for disaster recovery. Backup retention and rotation are described in our Data Retention Policy Section 5.
Backups are not accessible for normal use. They exist for restoration in the event of data corruption, outage, or security incident.
7. INCIDENT RESPONSE
If we become aware of a security incident that affects Client data, we will:
- Investigate the scope and impact
- Contain the incident and remediate the underlying cause
- Notify affected Clients within 72 hours of confirming the incident affects their data
- Provide follow-up detail as the investigation progresses
- Notify regulators where required by applicable law
Client notifications will include what happened, what data was affected, what we have done in response, and what steps Clients should take.
8. VULNERABILITY DISCLOSURE
8.1 How to report.
To report a security vulnerability in Tier1/AI, email:
You will receive an automated confirmation email immediately on receipt. A substantive response from our team will follow within 7 days.
8.2 Safe harbor.
Tier1/AI commits to good-faith engagement with security researchers who follow responsible disclosure. We will not pursue legal action against researchers who act in good faith and within the scope described in Section 8.3.
8.3 Scope.
The following types of testing are permitted:
- Testing against your own test account
- Reviewing publicly accessible endpoints for information disclosure
- Reporting suspected vulnerabilities you observe during normal use
The following are out of scope and are not authorized:
- Social engineering of Tier1/AI staff, contractors, or vendors
- Denial-of-service or resource exhaustion attacks
- Accessing accounts or data belonging to other users
- Exfiltrating data beyond the minimum needed to demonstrate the vulnerability
- Testing against third-party services on which Tier1/AI depends (Supabase, Vercel, Mailgun, etc. - report those directly to the respective provider)
- Physical attacks on Tier1/AI facilities or personnel
- Automated scanning that generates high volumes of traffic
8.4 What we ask.
When reporting, please:
- Give us a reasonable window (at least 30 days) to address the issue before public disclosure
- Provide enough detail for us to reproduce the issue
- Avoid actions that could harm Clients, Investor Contacts, or the integrity of the Service
Tier1/AI does not currently operate a paid bug bounty program.
9. WHAT WE DO NOT CLAIM
Honest disclosure of what is not yet in place:
- Tier1/AI does not currently hold SOC 2, ISO 27001, or equivalent certifications
- Tier1/AI does not currently conduct regular third-party penetration testing
- Tier1/AI does not currently operate a paid bug bounty program
We name these gaps because clients ask, and because honesty about what is and is not in place is a security posture in itself.
10. CONTACT
Vulnerability reports: support@tier1ai.io
Privacy and data requests: privacy@tier1ai.io
Legal notices: legal@tier1ai.io
General and business: services@tier1ai.io
Mailing address:
INS Digital Intelligence LLC
170 Ontario St
Honeoye Falls, NY 14472
United States