Your browser
Sends the application over HTTPS to this site.
Trust and data
Sofrito handles financial questions by showing what the records support, what remains uncertain, who can see the information, and which commitments are not yet complete.
Current policy boundary
A fuller notice and customer agreement must cover financial-data intake before that intake begins. Customer retention, backup, export, incident, and legal-request commitments are not silently filled in here.
That unfinished policy work is a launch dependency for customer financial-data intake, not a reason to invent generic security claims.
Sends the application over HTTPS to this site.
Hosts the public site, runs the server endpoint, and provides the human check.
Checks origin, size, closed choices, consent, abuse limits, and allowed fields.
Stores the accepted application in Postgres with public table access revoked.
What Sofrito collects and why
| Website requests | Cloudflare receives the IP address, time, requested URL, and browser identification needed to deliver and protect the site. Sofrito does not add advertising tags or tracking cookies. |
|---|---|
| Application information | Name, contact information, business profile, weekly sales range, the money question, growth plan, current systems and record availability, readiness, and consent choices. It is used to review the application, contact the applicant, and manage limited capacity. |
| Application safety signals | Submission time, browser identification, country reported by Cloudflare, referral source, and a one-way IP hash used for abuse limits and duplicate checks. The raw IP address is not stored in the application table. |
| Founding Access records | Agreed financial reports, statements, invoices, payroll summaries, expense evidence, business context, customer responses, actions, and follow-up evidence needed to produce the service. The exact intake and use must be set in the fuller customer notice and signed agreement before collection begins. |
Providers involved
Sofrito names the providers involved rather than describing the product as if it ran alone.
Public hosting, server functions, request delivery, security headers, abuse limits, and Turnstile on the application form.
Hosted Postgres for applications and product records. The public application page has no database credential and no direct table access.
Resend carries the new-application notification and replies. Google serves the page fonts. If an accepted applicant uses the enabled payment path, Stripe handles payment details; the application form does not collect card numbers.
Access boundaries
Receives a secure, scoped Living Brief for a published decision. Customers do not currently receive broad internal or cross-business access.
Uses an authenticated staff workspace. Account membership and business scope constrain what the operator can request.
Holds protected credentials and performs narrowly scoped requests. Credentials do not reach public JavaScript.
Newer product tables have Row Level Security enabled and forced, direct anonymous and public signed-in access revoked, and narrow server-role grants.
The application table separately denies all access to anonymous and public signed-in roles. A server-only endpoint is its write path.
Encryption and secrets
The site is served over HTTPS. Application information moves from Cloudflare's server endpoint to Supabase over HTTPS, and Supabase projects are encrypted at rest by default.
Sofrito does not claim end-to-end encryption or customer-managed encryption keys. Server secrets are runtime configuration, not committed public files or browser values.
AI use
The public application endpoint makes no AI call. In the product architecture, code calculates financial figures. AI may assist around evidence organization and language, while material conclusions remain human reviewed during Founding Access.
A missing record constrains the answer. A supported explanation does not become Verified simply because it sounds persuasive.
Received record and period.
Deterministic formula and exclusions.
Evidence-labeled judgment.
What happened after the decision.
Retention, deletion, backups, and export
These are not yet public Sofrito commitments. They must be completed in the fuller notice and customer agreement before intake.
History and corrections
Newer product records preserve publication versions, customer responses, action events, measurement evidence, outcomes, and operator attention history. Current state is derived from that record.
The application intake table is separate from this product history.
Human access
Authorized staff need access to agreed evidence to prepare and review the service. Customer access remains narrow, operator access remains account-scoped, and server/database grants follow least privilege.
The fuller notice must name the operational access and review expectations before customer financial intake.
Incidents, legal requests, and certifications
The repository has quality and correction controls, but a customer-facing security-incident procedure and notice commitment are not yet published. That must be completed before financial-data intake.
No public legal-request procedure is currently stated. Any future procedure must address validation, lawful scope, provider involvement, and customer notice where legally permitted.
Sofrito does not claim a security or privacy certification today. Provider certifications belong to those providers and do not automatically certify Sofrito.
Questions, correction requests, access requests, or concerns can be sent to hello@trysofrito.com.
Trust is part of the product
Read the current public policy or see how evidence becomes a decision.