SECURITY AT TIERSENTRY

Earn trust by collecting less and protecting what matters.

Security is being built into TierSentry’s operating model from the first customer interaction through the future brand portal.

Protect brand information

TierSentry limits collection to information needed for the Growth Review. Public visitors cannot read applications, internal notes, assignments, or other brand records.

Protect brand owners

The application uses consent, server-side validation, request-size limits, restricted origins, bot screening, and submission rate limits. No payment information or account password is requested.

Protect customer workspaces

Live customer access requires verified identity, multi-factor authentication, active brand membership, least-privilege permissions, and database-enforced brand isolation.

Protect TierSentry operations

Administrative work is separated from public access. Supabase is the system of record; Retool is the internal operating layer. Access is limited by role and reviewed as the team grows.

Reduce data exposure

Sensitive database credentials are never placed in the public website. Data is encrypted in transit, and the database platform provides encryption at rest.

Prepare for incidents

TierSentry maintains access controls, security-event records, retention rules, backup requirements, vulnerability checks, and an incident-response roadmap.

MVP CONTROL STATUS

Security promises tied to verifiable controls.

Implemented

Private intake

Applications cannot be read from the public website.

Implemented

Default-deny portal

Signed-in users see no brand information unless active membership and high-assurance session checks both pass.

Implemented

Security audit trail

Membership and customer-workspace changes create internal audit events.

In progress

Least-privilege operations

A restricted Retool role is ready to replace broad database credentials.

Required before live data

MFA enrollment

Every brand owner and TierSentry administrator must enroll a second factor.

Required before paid launch

Restore and response exercise

Backup recovery and incident-response procedures must be tested and recorded.

Security-ready is not SOC 2 Type I

These controls establish an auditable foundation. TierSentry will not describe itself as SOC 2 compliant or SOC 2 Type I until an independent licensed CPA firm completes the examination and issues the report.

Security or privacy question? Contact TierSentry.