Trust & Security

Where your data lives, who can touch it, and what we promise about how we handle it. Plain-language summary plus the legal-grade documents below.

At a glance

Tenant data isolationMulti-tenant by design — every query and write filters by tenant_id
Encryption in transitTLS 1.2+ for all API and dashboard traffic
Encryption at restAES-256 (managed by hosting provider)
AuthenticationBcrypt-hashed passwords; signed JWT for dashboard sessions
BackupsDaily snapshots, 7-day retention

Data we collect

We do not use your catalog or query data to train models that serve other tenants. Embeddings and rerank scores are computed and stored per-tenant.

Sub-processors

The third parties that process customer data on our behalf:

Sub-processorPurposeData scopeRegion
OpenAIQuery intent parsing, hypothetical-document generation, embeddingsSearch queries, product text snippetsUSA
Fly.ioApplication hostingAll catalog and analytics dataCustomer-selected region
SupabasePostgres database + authenticationAll catalog and account dataCustomer-selected region
FormspreeMarketing-site contact form processingEmail + free-text inquiry onlyUSA

Compliance & certifications

We're an early-stage company. Here's the honest current state:

If you're under procurement and need a security questionnaire filled out, we'll do it within five business days. Email security@partsift.com.

Data Processing Agreement (DPA)

Our standard DPA mirrors the EU SCCs and incorporates the sub-processor list above. Email legal@partsift.com with your entity name and we'll send a counter-signed copy within two business days. We can also countersign your DPA template if you have one.

Reporting a vulnerability

If you find a security issue, send a private note to security@partsift.com. We acknowledge within one business day and try to triage within five. We don't have a paid bounty program yet, but we will recognize you publicly (with consent) and credit your finding in the changelog.

Incident response

If we have an incident affecting your data, we will notify you within 72 hours of discovery via the email on your account, with a description of what was affected, what we know about scope, and what we're doing about it.

Partsift · This page reviewed April 27, 2026.