← Back to PopUpSync

Updated: August 2026

PopUpSync · AutonoViability AI Systems LLC

Security & Compliance

A detailed overview of the controls, infrastructure, and practices PopUpSync uses to protect your event data, vendor documents, and compliance records.

Important: PopUpSync certification status

PopUpSync is not itself SOC 2 or ISO 27001 certified. We are actively working toward these certifications (see Section 9). Our infrastructure providers — AWS, Vercel, and Neon — hold their own SOC 2 / ISO 27001 certifications for their platforms; these are vendor certifications, not PopUpSync's. We will update this page when certification milestones are reached.

TLS encryption in transitAES-256 at rest (AWS S3)Built on SOC 2 / ISO 27001 infraStripe PCI-DSS paymentsGDPR & CCPA rights
01

Encryption

What it is

Cryptographic encoding of data — both while it travels across the internet (in transit) and while it sits on disk (at rest).

Why it matters

Without encryption, data intercepted in transit or accessed on disk is immediately readable. For event management data — vendor certificates, permits, and compliance records — this would expose sensitive business information.

How we handle it

All traffic between your browser and PopUpSync is encrypted in transit using TLS/HTTPS, with certificates managed by Vercel. Vendor document files (insurance certificates, permits, licenses) are stored in AWS S3 with AES-256 server-side encryption at rest.
02

Trusted Infrastructure

Infrastructure-level certs: AWS · Vercel · Neon

What it is

The hosting, database, and file storage platforms that store and serve PopUpSync's application and data.

Why it matters

The security posture of your infrastructure providers directly impacts your data's safety, availability, and regulatory standing. Running on certified providers establishes a high baseline.

How we handle it

PopUpSync is built on providers that hold their own SOC 2 and ISO 27001 certifications: Vercel (application hosting), Neon PostgreSQL (database), and AWS S3 us-east-2 (document storage). These certifications cover those providers' own platforms and operations. They are not PopUpSync's certifications, but they establish the security baseline of the infrastructure PopUpSync runs on.
03

Secure Payments

Stripe PCI-DSS Level 1

What it is

Payment card data handling for PopUpSync subscription billing.

Why it matters

Payment card data is a high-value target. Mishandling it creates financial risk for customers and exposes the processor to PCI-DSS liability.

How we handle it

All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. PopUpSync never stores, transmits, or has access to raw credit card numbers, CVCs, or full card details. Card data goes directly to Stripe's secure systems.
04

Access Control & Tenant Isolation

What it is

The rules governing who can access which data within the platform, and how customer data is kept logically separate.

Why it matters

Without proper isolation, one customer's sensitive vendor and compliance data could be exposed to another customer — a critical failure in a multi-tenant SaaS product.

How we handle it

Accounts are protected by password authentication. All event records, vendor documents, compliance data, support threads, and notifications are scoped per account/tenant. One customer's data is logically isolated and inaccessible to other accounts.
05

Secrets Management

What it is

How API keys, database credentials, and other sensitive configuration values are stored and accessed.

Why it matters

Secrets embedded in source code are frequently leaked via public version control repositories, build logs, or commit history — one of the most common causes of credential compromise.

How we handle it

All API keys, database connection strings, and credentials are stored as platform environment variables via Vercel's secure secret management — not in application source code or version control. The repository contains no embedded secrets.
06

Data Lifecycle & Retention

What it is

How long PopUpSync retains different categories of data, and the schedule by which it is deleted.

Why it matters

Minimizing retained data reduces the blast radius of any potential incident and is a core principle of both GDPR and CCPA data minimization requirements.

How we handle it

  • Vendor documents (COIs, permits, licenses) are deleted when their event is archived.
  • Archived event records are auto-purged after 2 years.
  • Account data is deleted within 30 days of cancellation upon request.
07

Privacy & Data Rights

GDPR · CCPA

What it is

Your rights to access, correct, and delete personal data held by PopUpSync.

Why it matters

GDPR (EU Regulation 2016/679) and CCPA (California Civil Code § 1798.100 et seq.) give individuals enforceable rights over their personal data. PopUpSync is committed to honoring these rights.

How we handle it

Individuals may request access to or deletion of their personal data by contacting support@popupsync.com. Our full Privacy Policy covers data categories collected, legal bases for processing, and data subject rights in detail.
08

AI Processing

What it is

Where and how artificial intelligence is used within the PopUpSync platform.

Why it matters

When customer data is processed by third-party AI services, customers have a right to know — this is a GDPR/CCPA transparency requirement and a matter of operational trust.

How we handle it

PopUpSync uses the OpenAI API for automated document verification (checking that uploaded vendor documents are complete and unexpired) and support features. This processing is disclosed in the Privacy Policy. PopUpSync does not use customer data to train AI models.
09

Certification Roadmap

In progress — not yet certified

What it is

Formal security certifications we are actively pursuing.

Why it matters

SOC 2 Type II (AICPA Trust Services Criteria) and ISO 27001 (International Standard for Information Security Management) provide independent, audited assurance of security controls — the standard requested by enterprise procurement and security teams.

How we handle it

PopUpSync does not currently hold SOC 2 or ISO 27001 certification. We are actively working toward SOC 2 Type II and ISO 27001 certification. Procurement teams that require security documentation in the meantime should contact support@popupsync.com — we can provide available security information and answer specific questions.

Security & procurement questions

PopUpSync is operated by AutonoViability AI Systems LLC, 701 Market St Ste 110 PMB1958, Saint Louis, MO 63101. For security reviews, vulnerability reports, data subject requests, or procurement documentation, contact us at:

support@popupsync.com