Trust center
MasterGrid runs live event operations for organizations that hold sensitive site plans and staff data. This page explains how that data is protected, what is in place today, and what we are still working on. For anything security related, email security@mastergrid.io.
Compliance status
Where each item stands right now. We do not claim a certification, an audit or a test we have not completed.
- SOC 2 Type II
- In progress. We are preparing for our first audit.
- External penetration testing
- Planned. The report will be available to customers under NDA once complete.
- ISO 27001
- On the roadmap.
- GDPR and CCPA
- Supported. A Data Processing Addendum is available on request; we delete personal data on verified request.
How customer data is protected
- Every customer’s data is isolated per event and per organization with row-level security policies on every table in the database. Automated tests for those policies run on every change before it can ship.
- Customer uploads such as site plans, documents and evidence live in private storage and are served through short-lived signed links. The only files served publicly are organization and event logos, profile avatars and the images used in our own emails.
- All traffic is encrypted in transit with TLS. Data is encrypted at rest by our hosting providers.
- Multi-factor authentication (authenticator app with recovery codes) is available to every account.
- Access is role-based and scoped to an organization and an event. Invitations carry the role they were issued with.
- Application monitoring and analytics are separated per organization.
How changes reach production
- The production branch is protected. Every change arrives through a reviewed pull request.
- Continuous integration gates every change: type checks, lint, unit tests, a production build, database policy tests, and end-to-end browser tests.
- Changes are staged and tested on a separate staging environment before release.
- Production database changes are gated behind a manual switch and preceded by a full backup, retained for 90 days.
Infrastructure and subprocessors
MasterGrid is operated by a US-based team and hosted in the United States.
| Vendor | Purpose | Data involved |
|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage | Customer event data, account data, uploaded files |
| Vercel | Web hosting and content delivery | Request metadata |
| Sentry | Error monitoring | Technical error reports |
| PostHog | Product analytics | Usage events, per organization |
| Resend | Transactional email | Recipient addresses and message content |
| Mapbox | Base maps and geocoding | Map tiles requested; no customer records |
| Google Maps Platform | Satellite imagery | Map tiles requested; no customer records |
| Esri | Satellite imagery | Map tiles requested; no customer records |
| Nearmap | High-resolution aerial imagery | Map tiles requested; no customer records |
| Open-Meteo | Weather forecasts | Event site coordinates; no customer records |
| Anthropic | AI assistant features (Datum) | Content a user submits to the assistant |
We update this list before adding a subprocessor.
Report a vulnerability
If you find a security issue in MasterGrid, email security@mastergrid.io with the steps to reproduce it. We acknowledge reports within three business days.
We ask researchers to act in good faith: do not access or alter data that is not yours, do not run denial-of-service tests, do not attempt social engineering, and give us a reasonable amount of time to fix an issue before disclosing it.
We will not pursue legal action against good-faith research that follows this policy.
Requesting documents
Customers and prospective customers can request our security questionnaire responses, the Data Processing Addendum, and, once they exist, the SOC 2 report and the penetration test summary. Email security@mastergrid.io and tell us what you need and who to send it to.