Trust · Security overview

Your data, under contract.

SQEase processes legal study materials — sometimes drawn from confidential firm sources. Here's how we keep them safe, who else touches them, and how to tell us when something looks off.

AES-256 at restAll documents and database records
TLS 1.3 in transitAcross every connection
Certified infrastructureSOC 2 · ISO 27001 (Vercel, Google Cloud)
Per-user isolationYour records scoped to your account

How we secure the platform

Concrete controls — not vague reassurance — across data, access, infrastructure, and AI safety.

Data protection

Encryption · Isolation
  • AES-256 encryption at rest for all databases and document stores, provided by Google Cloud.
  • TLS 1.3 in transit for all client and inter-service traffic.
  • Per-user data isolation — your records are scoped to your account ID and enforced by database security rules.
  • Managed, encrypted storage with Google Cloud's built-in redundancy and durability.

Access & identity

Auth · Least privilege
  • Sign in with Google or email/password, managed by Firebase Authentication — we never store your password ourselves.
  • Single operator — one founder is the only person with production access; no team or contractors touch your data.
  • Reviewed changes — every production change goes through a pull request and a documented merge process.

Built on certified infrastructure

Inherited assurance
  • Hosted on Vercel — independently certified to SOC 2 Type II and ISO/IEC 27001.
  • Data, auth, and functions on Google Cloud / Firebase — SOC 2, ISO 27001, and ISO 27017/27018 certified.
  • Payments handled by Stripe, a PCI-DSS Level 1 service provider — we never see your card details.
  • Standard Data Processing Agreements in place with every infrastructure provider.

AI safety

Provider terms
  • Your uploads are never used as training data for any AI model.
  • No training on your data by default — our AI providers (Google, Anthropic, OpenAI) don't train on API inputs, and request logs are short-lived under each provider's API terms.
  • Every question is screened by an automated verification stage before it reaches you, and your materials stay scoped to your account.

Honest transparency

What we are — and aren't
  • SQEase is run by a single founder. No team, no contractors with data access.
  • One operator means a smaller attack surface — but also no 24/7 security team, and we won't pretend otherwise.
  • We comply with UK GDPR, the Data Protection Act 2018, and applicable consumer law.
  • Breach duty: we will notify the ICO and affected users within 72 hours of becoming aware of a personal-data breach.

Built on certified foundations

Live
UK GDPR & Data Protection Act 2018

We process personal data lawfully under UK data-protection law, with a standard DPA from every sub-processor.

Inherited
Vercel — SOC 2 Type II & ISO 27001

Our hosting and edge network is independently certified.

Inherited
Google Cloud — SOC 2 & ISO 27001/27017/27018

Our database, auth, functions, and storage run on certified Google Cloud infrastructure.

Inherited
Stripe — PCI-DSS Level 1

All card data is handled by Stripe and never touches our servers.

The difference between "certified" and "built on certified."

SQEase is a solo-run product, so we don't claim enterprise certifications we haven't earned ourselves.

What we can stand behind: we comply with UK GDPR and the Data Protection Act 2018, and we're built entirely on independently-certified infrastructure — Vercel, Google Cloud, and Stripe.

As we grow we intend to pursue our own SOC 2 and ISO 27001 — and we won't claim them until we hold the reports.

Who else processes your data

Every third party that touches your data, what they do, and the data-processing agreement we operate under with them.

Sub-processor
Role
DPA
Vercel
Website hosting, global edge/CDN, and frontend serverless functions.
Standard DPA
Google Cloud (Firebase)
Database, Cloud Functions, authentication, and file storage.
Standard DPA
Google (Gemini API)
Question generation and verification.
Standard DPA
Anthropic
Claude — exam-question drafting.
Standard DPA
OpenAI
GPT — independent question review.
Standard DPA
Stripe
Card payments and subscription billing (PCI-DSS Level 1).
Standard DPA
Resend
Transactional email delivery.
Standard DPA
Microsoft Clarity
Product analytics (heatmaps and session insights).
Standard DPA

We notify users of new sub-processors at least 30 days before they begin processing data.

Found a flaw? Tell us first.

We run a public, coordinated vulnerability-disclosure programme. We respond within 2 working days and publicly credit you with permission.

Safe-harbour rules

  • Test only against your own account.
  • Never read, modify, or exfiltrate data beyond what's needed to demonstrate the issue.
  • Never run automated scans exceeding 5 req/s.
  • Give us 90 days to fix before public disclosure.

Our thank-you

SQEase is a small startup with no cash bounty programme. What we can offer:

CriticalRCE, auth bypass, mass data exposure12 mo Pro
HighPrivilege escalation, single-user data leak6 mo Pro
MediumStored XSS, CSRF on sensitive action3 mo Pro
LowReflected XSS, minor info disclosure1 mo Pro
security.txtSubmit a report

Other security contacts

Procurement: finlay@sqease.uk · DPO: privacy@sqease.uk · Vulnerabilities: support@sqease.uk

PGP fingerprint · 4F9A 2B61 8C3D 7E04 5A2F · 1B98 6C5D 7E12 A38B 4F09

We use essential cookies to run SQEase and, with your permission, Microsoft Clarity to understand how the site is used. Analytics stay off unless you accept. Read our Cookie Policy.