Trust Center
Security you can build on.
Backpack Works builds B2B websites and operates Backpack OS, the platform teams use to monitor, optimize, and build their sites. The dashboard lives at app.backpack.works, with a site snippet served from cdn.backpack.works. This page explains how we protect the customer, account, and visitor data we handle — our architecture, compliance, and security practices.
Backpack OS uptime & statusCompliance & certifications
Where we are on each standard. We show real status — not aspirational claims.
SOC 2 Type II
PreparingWe have built our security program around the SOC 2 Trust Services Criteria (Security, Availability, and Confidentiality). We intend to pursue a formal SOC 2 Type II examination as the business grows — an audit is not yet scheduled.
ISO/IEC 27001
PreparingWe are structuring our Information Security Management System (ISMS) in line with ISO/IEC 27001:2022, with certification as a longer-term goal. No audit is currently scheduled.
GDPR
AlignedWe act as a data processor for our clients and follow the EU General Data Protection Regulation, including offering a Data Processing Agreement.
CCPA / CPRA
AlignedWe support our clients' obligations under the California Consumer Privacy Act and California Privacy Rights Act as a service provider.
Documents
Our policies and legal documents are published openly and downloadable as PDFs — plus ZIP bundles for attaching to vendor reviews. Audit reports become available as we complete each program.
| Document | Category | Access |
|---|---|---|
| All security policies (ZIP) | Policies | Download |
| Information Security Policy | Policies | Download |
| Business Continuity & DR Plan | Policies | Download |
| Data Processing Agreement (DPA) | Legal | Download |
| Sub-processor List | Legal | Download |
| Full trust center pack (ZIP) | Legal | Download |
| SOC 2 Type II Report | Reports | Planned |
| Penetration Test Summary | Reports | Planned |
Have a question or need something not listed here? Contact our security team.
Our security program
How we protect information across the business. Each area summarizes the controls we have in place today.
Data Protection
Data Security
Customer data is encrypted in transit and at rest, isolated per organization, and access follows least privilege.
Data Privacy
Customers are the controller of their account and visitor data; we act as processor and offer a DPA.
Encryption
TLS in transit, encryption at rest via our providers, and secrets kept out of source control.
Website-Visitor Data
Our analytics/CRO snippet is consent-aware and treats the customer as the controller of their visitors' data.
Access & Identity
Access Control
Least-privilege, role-based access across the platform and internal systems, with regular reviews.
Tenant Isolation
Every customer's data is scoped to their organization and enforced at the database layer with PostgreSQL Row-Level Security.
Endpoint Security
Company devices use full-disk encryption, screen-lock, anti-malware, and managed configuration.
Infrastructure
Infrastructure & Hosting
Backpack OS runs on managed, auto-scaling cloud platforms — Vercel, Supabase, and Cloudflare R2.
Network Security
Segmented environments, provider firewalls, and Cloudflare at the edge for the snippet and assets.
Application
Application Security
Secure coding, CSP and security headers, server-side validation, and SSRF/injection protections.
Secure Development
A defined SDLC with peer review, separate environments, and automated checks in CI.
Operations
Incident Response
A documented plan with defined roles, severity levels, and customer notification commitments.
Business Continuity & DR
Backups, redundant cloud infrastructure, and a recovery plan to keep client work moving.
Continuous Monitoring
Logging and alerting across key systems, with reviews of access and activity.
Governance
Risk Management
A recurring risk assessment process that drives our security priorities.
Vendor & Third-Party Risk
We vet vendors and sub-processors — including AI, analytics, and infrastructure providers — and publish a current list.
Corporate Security
Security awareness training, background-appropriate hiring, and email & account protection.
AI
AI & Data Handling
Only the data needed for a task, no training on customer data where providers allow, and human review of output.
Sub-processors
View details →Vercel
Application hosting & compute (app + snippet/CDN)
United States
Supabase
Managed PostgreSQL database, authentication & app data
United States
Cloudflare (R2 + CDN)
Object storage & CDN for the snippet and assets
Global (US)
Stripe
Billing & payments (no card data stored by us)
United States
Anthropic (Claude)
AI features — content, analysis & agents
United States
OpenAI
AI answer scanning & select AI features
United States
Perplexity
AI answer visibility scanning
United States
Google (Gemini)
AI answer visibility scanning
United States
Google (GA4, Search Console, Tag Manager, Ads, PageSpeed)
Customer-authorized analytics, tag & ads data (via OAuth)
United States
DataForSEO
SERP ranking & backlink data
United States
DeepL
Content translation
Germany / EU
GitHub
Optional code/CMS integration (OAuth)
United States
Webflow
Optional CMS integration (OAuth)
United States
WordPress
Optional CMS integration (customer-connected)
Varies
Prismic
Headless CMS integration
France / EU
WP Engine
Managed WordPress hosting for client sites
United States
Google Workspace
Email, documents & collaboration
United States
HubSpot
CRM & marketing automation
United States
Slack
Internal team communication
United States
1Password
Secrets & credential management
Canada
Policies
All 21 policies →Questions about our security?
Our team is happy to support your security review, complete a questionnaire, or share gated documentation under NDA.