Your improvement data describes how your operation runs. Here is what we do to protect it, and where we are still building.
NexLean.ai does not hold a SOC 2 report yet. We are building the controls and evidence for a SOC 2 Type I assessment first, then Type II. We will list the report here, and share it under NDA, once an independent auditor has issued it. Until then, the sections below describe what is actually in place today.
Every organization's data is separated at the database layer with row-level security on all tables. A query from one organization cannot read another organization's rows, even if application code has a bug. Admin actions, such as exporting or deleting an organization, are limited to organization admins and checked on the server.
We use these vendors to run the service. We will update this list when it changes.
| Vendor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | Account, organization, and challenge data |
| Vercel | Application hosting | Request metadata; no stored customer content |
| Anthropic | AI Kata Coach responses (Claude API) | Challenge context and coach messages, only when the Coach is used |
| Stripe | Subscription billing | Billing contact and payment details (card data never touches our servers) |
| Resend | Transactional email | Recipient email address and message content |
| Sentry | Error monitoring | Error and performance diagnostics |
If you find a security issue, email saintmba@nexlean.ai with the details. We will acknowledge it within two business days and keep you updated until it is fixed. Please give us a reasonable chance to fix an issue before disclosing it.
Reviewing us for procurement? Email us and we will complete your security questionnaire and sign a data processing agreement.
Last updated: September 2026