Your research data is your competitive edge. Here is exactly how we protect it: the architecture, the policies, and the parts we're still building. No black boxes.
Six areas, each documented in plain language. Click through for the full detail.
Tenant isolation enforced by the database itself, encryption everywhere, hardened headers, and mandatory 2FA on platform administration.
Read the security overview →Participants anonymous by default, GDPR and CCPA request handling built into the product, and a published retention schedule.
Read about data protection →A short, published list of every vendor that touches personal data, what they do, and 30 days' notice before any change.
See the full list →Graham runs on Anthropic's Claude. Your data isn't used to train models, usage is capped and logged, and humans stay in the loop.
How we use AI →Hourly backups stored with a separate provider, documented recovery targets, a live status page, and a 99.9% SLA with service credits.
Reliability & continuity →Found a vulnerability? We publish a clear reporting route, response commitments, and safe-harbor terms for good-faith research.
Report a vulnerability →The measures below are shipped and running today, and expanded in the security overview.
Every third party that touches personal data, and why. We give 30 days' notice before any change. Details on the sub-processors page.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, hosting | US |
| Vercel | Application hosting and delivery | US |
| Anthropic | Powers the Graham AI assistant, with no training on your data | US |
| Stripe | Payment processing; card numbers never touch our systems | US |
| Resend | Transactional and support email | US |
| Cloudflare | Bot protection and encrypted off-site backup storage | US |
| PureSpectrum | Optional panel recruitment; receives session outcomes only, never identities | US |
EEA/UK/Swiss transfers are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
The commitments behind this page are contractual, not decorative.
We don't yet hold SOC 2 or ISO 27001, and we won't put a badge here until we do. An independent penetration test is planned as part of our commercial launch, and SSO/SAML for Enterprise is on the roadmap. In the meantime, everything above is verifiable: our security commitments are written into the DPA and SLA, and Enterprise customers can request deeper documentation at sales@sortedresearch.com.
We're happy to walk your security, legal, or procurement team through the platform, complete questionnaires, and provide a countersigned DPA.