Perfs.

Security

*Buyer-facing page copy, not legalese. This is your SOC 2 substitute — the honesty in the last two sections is what makes it work.*

Last updated: [DATE]

How we protect your review data

Performance reviews are among the most sensitive documents a company produces. Here's exactly how Perfs handles them — in plain terms, with nothing dressed up.

Isolation between companies

Every company's data is separated at the database level using row-level security in Postgres. This isn't application logic that could be bypassed by a bug in our code — the database itself refuses to return one company's rows to another company's session. A query that tries to reach across that boundary returns nothing.

Sign-in

Perfs uses emailed sign-in links. We never ask for, create, or store a password, which means there are no password hashes to breach and no credentials of yours to reuse elsewhere. Links are single-use and expire.

Encryption

All traffic between your browser and Perfs is encrypted in transit over TLS. Data is encrypted at rest on disk by our database provider.

Payments

Payments are handled entirely by Stripe. Card numbers never reach our servers — we see only a transaction record and the last four digits. Stripe is certified PCI DSS Level 1, the highest level in the standard.

Where it runs

LayerProviderNotes
Database and authSupabaseHosted in West US (North California)
Application hostingVercelUnited States
PaymentsStripePCI DSS Level 1
Email deliveryResendReview requests, reminders, results

Supabase and Vercel each maintain SOC 2 Type II compliance for the infrastructure Perfs runs on. Their reports are available directly from them.

Who can see your data

Perfs is a small team. Administrative access to production systems is limited to Tahr Inc.'s founder. That access exists so we can respond to support requests and fix problems — it's used for that and nothing else. We don't read review content out of curiosity, we don't mine it for insights about your company, and we don't share it.

We think being direct about this is more useful than claiming an access-control regime that a company our size doesn't have.

Backups

The database is backed up daily and retained on a rolling 7-day cycle.

Reporting a vulnerability

If you think you've found a security issue, email security@runperfs.com. We'll acknowledge it within two business days and keep you updated until it's resolved. We won't pursue legal action against anyone who reports a vulnerability in good faith and gives us reasonable time to fix it before disclosing it.

If something goes wrong

If we become aware of a breach affecting your data, we'll notify affected account administrators within 72 hours of confirming it, with what we know, what we're doing, and what you should do.

Your data isn't locked in

You can export your review data from Perfs in a standard machine-readable format, at no charge, whenever you want — including after you stop being a customer.

We also delete — self-serve, no ticket. An administrator can delete the organization from Settings: access ends immediately, production data is permanently deleted when the 30-day grace window closes (cancellable until then), and backups age out within 7 days after that.

About SOC 2

We don't have a SOC 2 report. Getting one costs a small company tens of thousands of dollars and several months, and we'd rather pass that saving on to you than charge enterprise prices to fund an audit.

What we'd suggest instead: read this page, ask us anything you want about how the system works, and note that the underlying infrastructure — Supabase, Vercel, Stripe — is SOC 2 audited by providers far larger than us. If your security team needs a questionnaire filled out, send it over. We answer them honestly, including where the answer is "no".

Questions

Email hello@runperfs.com. A person reads it.

---