We take the security of your food safety documentation seriously. Here's how we protect your data.
Food Safety Audit is designed with a "references only" architecture. We store links and metadata about your documents, but your actual files remain securely in your Google Drive. This means:
We follow the principle of least privilege, requesting only the minimum permissions necessary to provide our service.
| Scope | Purpose | What We Access |
|---|---|---|
openid | Verify your identity | Your Google account ID |
email | Account identification | Your email address |
profile | Display your name | Your name and profile picture |
drive.readonly | Read document metadata | File names, IDs, and folder structure (read-only) |
We partner with industry-leading service providers to deliver our platform securely.
| Provider | Purpose | Location | Data Processed |
|---|---|---|---|
| Google Cloud Platform | Authentication (OAuth 2.0) | United States | Account credentials, authentication tokens |
| Stripe | Payment processing | United States | Billing information, payment details |
| TiDB Cloud (PingCAP) | Database hosting | United States | Application data, user records, document metadata |
| Cloudflare | CDN, DDoS protection, DNS | Global | Traffic data, IP addresses |
| OpenAI | AI document categorization | United States | Document metadata (transient, not stored) |
| Manus Platform | Application hosting | United States | Application runtime data |
If you discover a security vulnerability, please report it to:
[email protected]We will acknowledge receipt within 48 hours and work with you to understand and address the issue.
We are committed to continuous improvement of our security posture.
Our security controls align with SOC 2 Type I requirements. We implement encryption, access controls, audit logging, and incident response procedures.
We are working toward SOC 2 Type II certification to provide independent verification of our security controls.