Security documentation

    How we handle and protect your data

    This page is maintained by JD Equity Partners, LLC. It describes the controls that are actually in place today — it is not a certification, an audit report, or a guarantee against every possible incident.

    Last updated: September 1, 2026

    Encryption

    Every connection to this site and to our backend is served over HTTPS (TLS), so data is encrypted in transit. Our database, file storage, and backups are hosted on managed infrastructure with encryption at rest enabled by the provider.

    Passwords are stored as salted hashes — never in readable form — and leaked-password protection blocks passwords found in known public breaches. API keys and provider credentials are stored server-side only; once saved, they are never displayed back in full.

    Card numbers are never transmitted to or stored on our systems. Stripe's hosted checkout handles them end to end.

    Access control

    Data is separated per account at the database level with row-level security, so one client's records cannot be read from another client's session. Administrative screens and actions are restricted to our staff accounts and enforced on the server, not merely hidden in the interface.

    Only the two founders hold administrative access. We do not ask for, and never store, passwords to your third-party accounts — integrations use official OAuth or API keys you provide.

    Data retention

    We keep as little as we can for as long as we need it. Specifically:

    • Account and profile records

      Kept while you are a client, then for accounting and legal records.

    • Quotes, orders, invoices

      Kept as financial records for as long as tax and accounting rules require.

    • Requests, tickets and replies

      Kept for the life of the account so support history stays intact.

    • Uploaded files and deliverables

      Kept in your portal until you ask us to remove them.

    • Operational and error logs

      Rolling cleanup — transient logs age out automatically.

    • Product analytics events

      Only collected if you accept analytics cookies; removable on request.

    You can request a copy, a correction, or deletion at any time by emailing us — we confirm within 1 business day.

    Incident reporting

    If we become aware of a security incident affecting your data, we investigate immediately, contain it, and contact affected clients directly by email and phone with what we know, what we've done, and what you should do — without waiting for a complete picture.

    To report something to us, email JDEquityPartners@gmail.com with the subject "Security report", or call (313) 741-2912. We acknowledge within 1 business day and will not pursue action against good-faith researchers who give us a reasonable chance to fix an issue first. Please don't access other people's data while testing.

    Providers and subprocessors

    Running the platform means trusting a short list of established providers. Each one receives only what it needs to do its job:

    ProviderPurposeData involved
    StripePayments, subscriptions, invoices, receiptsBilling contact, purchase history. Card numbers are handled by Stripe only.
    SupabaseDatabase, authentication, file storageAccount records, requests, reports, uploaded files.
    ResendTransactional email deliveryEmail address and message content for receipts, sign-in links, notifications.
    FirecrawlPublic web research for proposalsYour public website and listing URLs.
    PostHogProduct analyticsPseudonymous usage events, subject to your cookie choice.
    GoogleAdvertising measurementAd interaction signals, subject to your cookie choice.

    We don't sell your data, and we don't add new providers that touch client data without updating this list.

    Shared responsibility

    We're responsible for how this platform handles your data and for the work you paid for. Our providers are responsible for the security of their own platforms.

    You're responsible for keeping your sign-in credentials private, for the accuracy of what you give us, and for the accounts you choose to connect to your portal.

    Need something in writing for your team?

    Download the privacy summary, or ask us directly — we'll answer specific security questions in writing.