Security and trust
What protects your work,
and what does not yet.
For the person who has to sign off on Deliverd: where your data lives, who can reach it, how identity works and the gaps as they stand today. The full detail is on the security page.
Where your data lives
Stored in London, served from London
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication and file storage. Holds accounts, access grants, audit history and published report files. | London, United Kingdom (eu-west-2) |
| Vercel | Application hosting and content delivery. Runs the code that serves the product and streams published reports. | London, United Kingdom (lhr1); static files from Vercel's global edge network |
| Stripe | Payments and subscription billing on paid plans. Card details go to Stripe directly and never reach our servers. | United States and Ireland |
| Resend | Transactional email: invitations, verification codes, notifications. Receives the recipient address and message body. | United States |
| Google Analytics | Aggregate traffic measurement on these marketing pages only. Loads nothing until you accept, and never runs in the product or on a published report. | United States |
| Anthropic, PBC | Ethics model screen, only when an organisation switches it on. Receives an approval request's title, description, action and input — never a field the action marks restricted. | United States |
The same list is in the privacy policy. A data processing agreement under Article 28 of the GDPR is available — ask us for it.
How it is built
The link is not the permission
Two origins
The product and published reports are served from different origins, so a report — HTML an AI wrote — can never read your session or call the product.
Read the detail about Two originsAccess decided on every request
A link is not a permission. Who may open a report is checked each time it is served, against your own sign-in, not baked into the address.
Read the detail about Access decided on every requestChecked before it is published
Every publish is scanned for credentials — cloud, GitHub, Slack, Stripe and model-provider keys, and private keys — and blocked when one is found. Scripting worth a second look raises a warning on the version.
Read the detail about Checked before it is publishedAn audit trail nobody can edit
Audit events are insert-only: a database trigger rejects every update and delete, including from our own service key. Retention is the one exception, on your plan's schedule.
Read the detail about An audit trail nobody can editIdentity and access
Your sign-in, your directory, your roles
- Single sign-on with SAML or OpenID Connect, enforceable per domain — included in Team, Business and Enterprise.
- Directory Sync (SCIM 2.0) from Microsoft Entra, Okta and other directories: people are provisioned and removed by your directory — included in Business and Enterprise.
- Agent identities, each scoped to the workspaces and reports it may touch — included in Team, Business and Enterprise.
- Roles for owners, administrators, security and billing administrators, workspace administrators, publishers and viewers. Readers and approvers never need a paid seat.
Your data
Kept for you, not trained on
- No. Deliverd does not use your content to train models, and your reports are not sent to a model provider. There is one opt-in exception, and it is not about training: an organisation on Business and above that switches on the ethics model screen sends the title, description, action and input of each request an agent makes to Anthropic, so a model can suggest concerns for the approver. It is off unless an administrator turns it on.
- Audit history is kept for 90 days on Team and 365 days on Business and Enterprise, and longer by agreement on Enterprise.
- Legal holds — included in Enterprise — stop retention from deleting what somebody undertook to preserve, and survive a downgrade.
What we do not have yet
The gaps, as they stand today
- No third-party certification. We do not hold SOC 2 or ISO 27001. We will not imply otherwise while that is true.
- The rest — scanning, rate limiting, identity edge cases — is listed plainly in section 9 of the security page.
Send us your security questionnaire.
We answer it against the security page rather than around it, and a person reads every one.