Backpack Works logo

Trust Center

Security you can build on.

Backpack Works builds B2B websites and operates Backpack OS, the platform teams use to monitor, optimize, and build their sites. The dashboard lives at app.backpack.works, with a site snippet served from cdn.backpack.works. This page explains how we protect the customer, account, and visitor data we handle — our architecture, compliance, and security practices.

Backpack OS uptime & status

Compliance & certifications

Where we are on each standard. We show real status — not aspirational claims.

SOC 2 Type II

Preparing

We have built our security program around the SOC 2 Trust Services Criteria (Security, Availability, and Confidentiality). We intend to pursue a formal SOC 2 Type II examination as the business grows — an audit is not yet scheduled.

ISO/IEC 27001

Preparing

We are structuring our Information Security Management System (ISMS) in line with ISO/IEC 27001:2022, with certification as a longer-term goal. No audit is currently scheduled.

GDPR

Aligned

We act as a data processor for our clients and follow the EU General Data Protection Regulation, including offering a Data Processing Agreement.

CCPA / CPRA

Aligned

We support our clients' obligations under the California Consumer Privacy Act and California Privacy Rights Act as a service provider.

Documents

Our policies and legal documents are published openly and downloadable as PDFs — plus ZIP bundles for attaching to vendor reviews. Audit reports become available as we complete each program.

Have a question or need something not listed here? Contact our security team.

Our security program

How we protect information across the business. Each area summarizes the controls we have in place today.

Data Protection

Data Security

Customer data is encrypted in transit and at rest, isolated per organization, and access follows least privilege.

Data Privacy

Customers are the controller of their account and visitor data; we act as processor and offer a DPA.

Encryption

TLS in transit, encryption at rest via our providers, and secrets kept out of source control.

Website-Visitor Data

Our analytics/CRO snippet is consent-aware and treats the customer as the controller of their visitors' data.

Access & Identity

Access Control

Least-privilege, role-based access across the platform and internal systems, with regular reviews.

Tenant Isolation

Every customer's data is scoped to their organization and enforced at the database layer with PostgreSQL Row-Level Security.

Endpoint Security

Company devices use full-disk encryption, screen-lock, anti-malware, and managed configuration.

Infrastructure

Infrastructure & Hosting

Backpack OS runs on managed, auto-scaling cloud platforms — Vercel, Supabase, and Cloudflare R2.

Network Security

Segmented environments, provider firewalls, and Cloudflare at the edge for the snippet and assets.

Application

Application Security

Secure coding, CSP and security headers, server-side validation, and SSRF/injection protections.

Secure Development

A defined SDLC with peer review, separate environments, and automated checks in CI.

Operations

Incident Response

A documented plan with defined roles, severity levels, and customer notification commitments.

Business Continuity & DR

Backups, redundant cloud infrastructure, and a recovery plan to keep client work moving.

Continuous Monitoring

Logging and alerting across key systems, with reviews of access and activity.

Governance

Risk Management

A recurring risk assessment process that drives our security priorities.

Vendor & Third-Party Risk

We vet vendors and sub-processors — including AI, analytics, and infrastructure providers — and publish a current list.

Corporate Security

Security awareness training, background-appropriate hiring, and email & account protection.

AI

AI & Data Handling

Only the data needed for a task, no training on customer data where providers allow, and human review of output.

Sub-processors

View details →

Vercel

Application hosting & compute (app + snippet/CDN)

United States

Supabase

Managed PostgreSQL database, authentication & app data

United States

Cloudflare (R2 + CDN)

Object storage & CDN for the snippet and assets

Global (US)

Stripe

Billing & payments (no card data stored by us)

United States

Anthropic (Claude)

AI features — content, analysis & agents

United States

OpenAI

AI answer scanning & select AI features

United States

Perplexity

AI answer visibility scanning

United States

Google (Gemini)

AI answer visibility scanning

United States

Google (GA4, Search Console, Tag Manager, Ads, PageSpeed)

Customer-authorized analytics, tag & ads data (via OAuth)

United States

DataForSEO

SERP ranking & backlink data

United States

DeepL

Content translation

Germany / EU

GitHub

Optional code/CMS integration (OAuth)

United States

Webflow

Optional CMS integration (OAuth)

United States

WordPress

Optional CMS integration (customer-connected)

Varies

Prismic

Headless CMS integration

France / EU

WP Engine

Managed WordPress hosting for client sites

United States

Google Workspace

Email, documents & collaboration

United States

HubSpot

CRM & marketing automation

United States

Slack

Internal team communication

United States

1Password

Secrets & credential management

Canada

Questions about our security?

Our team is happy to support your security review, complete a questionnaire, or share gated documentation under NDA.