Security first

Your security is our priority

How EQUATION protects your evidence, decisions and payments — stated plainly, without claims we cannot back.

How We Protect You

Our comprehensive security approach covers every aspect of the platform.

Encryption in transit

Traffic to EQUATION is served over HTTPS/TLS. Credentials and tokens are never sent in the clear.

Secure authentication

Passwords are stored only as salted hashes, multi-factor authentication is available, and sessions can be reviewed and revoked.

Organization isolation

Each organization's evidence, decisions and partnership records stay inside its own workspaces. Access follows membership, role and delegation.

Payments through Stripe

Card data is handled by Stripe, a PCI DSS Level 1 service provider. Card numbers never touch EQUATION servers.

Verified identities

Account ownership is proven by verified email or platform connection, never by a matching username.

Your data, your models

One customer's data is not used to train another customer's models without explicit permission.

Secure Payments

Covered partnership payments run through Stripe. Funds for covered work are held until the work is approved, when authorization and the payment provider allow.

Card processing by Stripe, a PCI DSS Level 1 provider
Held funds released on approval, subject to provider authorization
Payouts only to verified accounts
Buyer-paid commission shown before funding

Infrastructure

  • Enterprise-grade cloud hosting
  • Multi-region data redundancy
  • 99.9% uptime SLA
  • Automated scaling and failover

Compliance & Certifications

Where we stand today, including what is not yet certified.

PCI DSS

Via Stripe (Level 1)

GDPR

Data-subject rights supported

CCPA

Consumer rights supported

SOC 2

Not yet certified

Security Practices

The practices behind the product, described as they are.

Secure development

  • Changes are reviewed before release
  • Automated tests run on every change
  • Dependencies are tracked and updated

Access control

  • Role-based access inside each organization
  • Least-privilege delegation for agencies and clients
  • Support access requires a stated reason and is recorded

Reporting an issue

  • Report a suspected vulnerability through our contact page
  • Live platform checks on the status page
  • Affected customers are told what happened and what changed

Security Researcher Program

We value the security research community. If you discover a vulnerability, please report it responsibly. We offer rewards for valid security findings.

Report a Vulnerability

Found a bug?

hi@equation.so

Have Security Questions?

Our security team is available to answer questions about our practices and help with security-related concerns.