Resplendent Data
Trust Center

How we secure the product and handle your data.

Get accessView controls

Last reviewed: August 2026 · Questions? support@resplendentdata.com

Overview

Everything here is live in production unless marked as in progress.

Compliance

Product Security

  • Audit LoggingHistory of exports, configuration changes, and user access
  • Multi-Factor AuthenticationTOTP authenticator apps with hashed recovery codes; admins can require 2FA company-wide
  • Single Sign-On (Microsoft)Sign in with Entra ID on Business plans and up
  • Role-Based Access ControlGranular dashboard, dataset, and feature permissions
  • Session ManagementIdle logout and per-device revocation
  • Adversarial AI code reviewEvery change is reviewed by the latest frontier AI models in an adversarial, attacker-minded pass before it ships

Data Security

  • Encryption-in-transitTLS 1.2 minimum, TLS 1.3 negotiated, HSTS enforced
  • Encryption-at-restFull-disk encryption on our infrastructure, including backups
  • Per-tenant credential encryptionEvery customer gets a unique 256-bit key. Integration credentials are encrypted with AES + HMAC (Fernet) and a fresh random salt on every write
  • Data BackupsEncrypted database backups with encrypted off-site storage
  • You choose what gets syncedOnly the tables and columns you select ever reach us. Deleted datasets vanish immediately; synced data is never backed up

AI Security

  • Zero data retentionEric runs exclusively on an enterprise OpenAI endpoint governed by a zero data retention (ZDR) agreement: prompts, outputs, and attachments are never stored on OpenAI systems, never appear in any log, and are contractually barred from model training or fine-tuning. Your data makes one round trip and is gone.

Infrastructure

  • Dedicated infrastructureDedicated hardware in DataBank BOS1, Boston US
  • Automated certificate rotationSSL certificates rotate automatically every ~90 days with no expiry gaps
  • DataBank SOC 2 Type 2Covers their colocation service; report available on request

Security Grades

Data Privacy

  • Data Breach NotificationsIf anything ever goes wrong, you hear it from us first: you know when we know
  • Your data is your dataSynced data is only for you and your company. We don't use it, we don't want to see it, and we definitely don't want to talk about your unmentionables

Access Control

  • Tenant separationOne customer's encryption key can never decrypt another customer's data
  • Least-privilege syncSync credentials only see the columns you select

Subprocessors

These companies handle customer or website data on our behalf. The full list is in our DPA Annex I.

CompanyPurposeLocationAdditional DetailsTrust Site
OpenAIEric and other AI featuresUnited StatesZero data retention; not used for model trainingtrust.openai.com ↗
HubSpotCRM and customer communicationsUnited Statestrust.hubspot.com ↗
Google AnalyticsWebsite analyticsUnited StatesMarketing site onlyprivacy.google.com/businesses ↗
PostHogProduct analyticsUnited Statestrust.posthog.com ↗
StripePayments processingUnited StatesCard data never touches Resplendent systemsdocs.stripe.com/security ↗
SentryError monitoring and diagnosticsUnited Statessentry.io/trust ↗

Documents

📄
Legal · public
📄
Legal · public
📄
Docs · public
📄
Docs · public
🔒
Reports · gated
🔒
Legal · gated

Request documentation

Need a security packet, report, or questionnaire filled out? Email us and we’ll get it to you.

Email support@resplendentdata.com