Skip to content

Trust and data

Clear about the evidence. Clear about the access. Clear about the gaps.

Sofrito handles financial questions by showing what the records support, what remains uncertain, who can see the information, and which commitments are not yet complete.

Current policy boundary

The public Privacy policy covers this website and the Founding Access application.

A fuller notice and customer agreement must cover financial-data intake before that intake begins. Customer retention, backup, export, incident, and legal-request commitments are not silently filled in here.

That unfinished policy work is a launch dependency for customer financial-data intake, not a reason to invent generic security claims.

01

Your browser

Sends the application over HTTPS to this site.

02

Cloudflare

Hosts the public site, runs the server endpoint, and provides the human check.

03

Sofrito endpoint

Checks origin, size, closed choices, consent, abuse limits, and allowed fields.

04

Supabase

Stores the accepted application in Postgres with public table access revoked.

What Sofrito collects and why

Different information has different boundaries.

Website requestsCloudflare receives the IP address, time, requested URL, and browser identification needed to deliver and protect the site. Sofrito does not add advertising tags or tracking cookies.
Application informationName, contact information, business profile, weekly sales range, the money question, growth plan, current systems and record availability, readiness, and consent choices. It is used to review the application, contact the applicant, and manage limited capacity.
Application safety signalsSubmission time, browser identification, country reported by Cloudflare, referral source, and a one-way IP hash used for abuse limits and duplicate checks. The raw IP address is not stored in the application table.
Founding Access recordsAgreed financial reports, statements, invoices, payroll summaries, expense evidence, business context, customer responses, actions, and follow-up evidence needed to produce the service. The exact intake and use must be set in the fuller customer notice and signed agreement before collection begins.

Providers involved

A short, named service chain.

Sofrito names the providers involved rather than describing the product as if it ran alone.

Cloudflare

Public hosting, server functions, request delivery, security headers, abuse limits, and Turnstile on the application form.

Supabase

Hosted Postgres for applications and product records. The public application page has no database credential and no direct table access.

Resend, Google Fonts, and Stripe

Resend carries the new-application notification and replies. Google serves the page fonts. If an accepted applicant uses the enabled payment path, Stripe handles payment details; the application form does not collect card numbers.

Access boundaries

The public page, customer brief, operator workspace, server, and database are not the same boundary.

01

Customer

Receives a secure, scoped Living Brief for a published decision. Customers do not currently receive broad internal or cross-business access.

02

Operator

Uses an authenticated staff workspace. Account membership and business scope constrain what the operator can request.

03

Server

Holds protected credentials and performs narrowly scoped requests. Credentials do not reach public JavaScript.

04

Database

Newer product tables have Row Level Security enabled and forced, direct anonymous and public signed-in access revoked, and narrow server-role grants.

The application table separately denies all access to anonymous and public signed-in roles. A server-only endpoint is its write path.

Encryption and secrets

Protected in transit, provider-encrypted at rest, and no public database secret.

The site is served over HTTPS. Application information moves from Cloudflare's server endpoint to Supabase over HTTPS, and Supabase projects are encrypted at rest by default.

Sofrito does not claim end-to-end encryption or customer-managed encryption keys. Server secrets are runtime configuration, not committed public files or browser values.

What the current code enforces

  • Exact-origin checks on application submissions
  • Turnstile verification and request limits
  • Allowed-field and closed-choice checks
  • Server-only database key
  • No-cache and no-index response headers
  • Public deployment allowlist

AI use

AI may help explain. It does not get to rewrite the financial truth.

The public application endpoint makes no AI call. In the product architecture, code calculates financial figures. AI may assist around evidence organization and language, while material conclusions remain human reviewed during Founding Access.

A missing record constrains the answer. A supported explanation does not become Verified simply because it sounds persuasive.

Claim lineageInspectable
1
Source

Received record and period.

2
Calculation

Deterministic formula and exclusions.

3
Finding

Evidence-labeled judgment.

4
Action and outcome

What happened after the decision.

Retention, deletion, backups, and export

Published commitments and open commitments are separated.

Published for applications

  • Sofrito's policy commitment is to delete declined or withdrawn applications within 24 months after review.
  • A restricted database deletion procedure exists, but no automatic schedule is currently verified. Sofrito must run the procedure operationally until scheduling is implemented and tested.
  • An applicant may request earlier deletion, correction, or a copy by email.
  • Sofrito confirms a request within five business days and completes it within thirty.
  • Joined-business applications move under the customer agreement after the engagement begins.

Required before customer financial-data intake

  • A verified automatic schedule or documented recurring manual procedure for the 24-month application deletion commitment
  • Customer record-retention schedule and end-of-engagement deletion steps
  • Active database backup and recovery coverage, including the plan-specific window
  • Customer export format and delivery procedure
  • What happens to deleted records still present in a provider backup

These are not yet public Sofrito commitments. They must be completed in the fuller notice and customer agreement before intake.

History and corrections

New facts supersede old ones. They do not silently erase them.

Newer product records preserve publication versions, customer responses, action events, measurement evidence, outcomes, and operator attention history. Current state is derived from that record.

The application intake table is separate from this product history.

Human access

Founding Access includes human review, so “zero access” would be false.

Authorized staff need access to agreed evidence to prepare and review the service. Customer access remains narrow, operator access remains account-scoped, and server/database grants follow least privilege.

The fuller notice must name the operational access and review expectations before customer financial intake.

Incidents, legal requests, and certifications

No borrowed trust marks. No missing procedure disguised as policy.

Incident handling

The repository has quality and correction controls, but a customer-facing security-incident procedure and notice commitment are not yet published. That must be completed before financial-data intake.

Legal requests

No public legal-request procedure is currently stated. Any future procedure must address validation, lawful scope, provider involvement, and customer notice where legally permitted.

Certifications

Sofrito does not claim a security or privacy certification today. Provider certifications belong to those providers and do not automatically certify Sofrito.

Questions, correction requests, access requests, or concerns can be sent to hello@trysofrito.com.

Trust is part of the product

Know the number. Know the evidence. Know the boundary.

Read the current public policy or see how evidence becomes a decision.