Security and trust

What protects your work,
and what does not yet.

For the person who has to sign off on Deliverd: where your data lives, who can reach it, how identity works and the gaps as they stand today. The full detail is on the security page.

Where your data lives

Stored in London, served from London

ProviderWhat it doesWhere
SupabaseDatabase, authentication and file storage. Holds accounts, access grants, audit history and published report files.London, United Kingdom (eu-west-2)
VercelApplication hosting and content delivery. Runs the code that serves the product and streams published reports.London, United Kingdom (lhr1); static files from Vercel's global edge network
StripePayments and subscription billing on paid plans. Card details go to Stripe directly and never reach our servers.United States and Ireland
ResendTransactional email: invitations, verification codes, notifications. Receives the recipient address and message body.United States
Google AnalyticsAggregate traffic measurement on these marketing pages only. Loads nothing until you accept, and never runs in the product or on a published report.United States
Anthropic, PBCEthics model screen, only when an organisation switches it on. Receives an approval request's title, description, action and input — never a field the action marks restricted.United States

The same list is in the privacy policy. A data processing agreement under Article 28 of the GDPR is available — ask us for it.

How it is built

The link is not the permission

Two origins

The product and published reports are served from different origins, so a report — HTML an AI wrote — can never read your session or call the product.

Read the detail about Two origins

Access decided on every request

A link is not a permission. Who may open a report is checked each time it is served, against your own sign-in, not baked into the address.

Read the detail about Access decided on every request

Checked before it is published

Every publish is scanned for credentials — cloud, GitHub, Slack, Stripe and model-provider keys, and private keys — and blocked when one is found. Scripting worth a second look raises a warning on the version.

Read the detail about Checked before it is published

An audit trail nobody can edit

Audit events are insert-only: a database trigger rejects every update and delete, including from our own service key. Retention is the one exception, on your plan's schedule.

Read the detail about An audit trail nobody can edit

Identity and access

Your sign-in, your directory, your roles

  • Single sign-on with SAML or OpenID Connect, enforceable per domain — included in Team, Business and Enterprise.
  • Directory Sync (SCIM 2.0) from Microsoft Entra, Okta and other directories: people are provisioned and removed by your directory — included in Business and Enterprise.
  • Agent identities, each scoped to the workspaces and reports it may touch — included in Team, Business and Enterprise.
  • Roles for owners, administrators, security and billing administrators, workspace administrators, publishers and viewers. Readers and approvers never need a paid seat.

Your data

Kept for you, not trained on

  • No. Deliverd does not use your content to train models, and your reports are not sent to a model provider. There is one opt-in exception, and it is not about training: an organisation on Business and above that switches on the ethics model screen sends the title, description, action and input of each request an agent makes to Anthropic, so a model can suggest concerns for the approver. It is off unless an administrator turns it on.
  • Audit history is kept for 90 days on Team and 365 days on Business and Enterprise, and longer by agreement on Enterprise.
  • Legal holds — included in Enterprise — stop retention from deleting what somebody undertook to preserve, and survive a downgrade.

What we do not have yet

The gaps, as they stand today

  • No third-party certification. We do not hold SOC 2 or ISO 27001. We will not imply otherwise while that is true.
  • The rest — scanning, rate limiting, identity edge cases — is listed plainly in section 9 of the security page.

Send us your security questionnaire.

We answer it against the security page rather than around it, and a person reads every one.