Trust
HardPan™ stores the records that prove your sites are operating in compliance. That data is sensitive in three ways: it identifies your facilities and employees, it has financial value to you (renewal costs, fines avoided), and it has evidentiary weight if an inspector or regulator ever asks for it. We treat security as a baseline expectation, not a marketing line. This page describes what is in place today and what we are working toward.
All traffic between your browser, the HardPan application, and our subprocessors is encrypted with TLS 1.2 or higher. Customer documents stored in AWS S3 are encrypted at rest with AES-256, using AWS-managed keys (SSE-S3). Database storage at Airtable and Noloco is encrypted at rest per their respective infrastructure controls. Email delivery from the Service is sent through Mailgun over TLS.
Each customer is provisioned with a dedicated Airtable base, not a shared multi-tenant schema with row-level security. This means your data lives in its own database container, with its own access permissions, separate from every other customer’s data. Customer portals served by Noloco connect to your base only. There is no shared connection pool through which data could cross between customers.
Customer users authenticate through Noloco with email and password. Operator and Regional tiers include Azure AD single sign-on, so your team uses the same credentials and MFA policy you already enforce through Microsoft 365. Access within the portal is role-based: site leads see their own sites; corporate sees the rollup; auditors get scoped read-only links. We do not use shared logins, and we do not store passwords in plain text.
HardPan is built on a small, deliberate set of platforms. The data layer is Airtable. The customer portal is Noloco. Automation runs on n8n Cloud. Non-Microsoft document storage is AWS S3 (US regions). Email is Mailgun. Customers on Microsoft 365 who purchase the SharePoint Sync add-on authorize document metadata exchange through Microsoft Graph. Each of these providers has its own security program (Airtable SOC 2 Type II, AWS SOC 2 / SOC 3 / ISO 27001, Mailgun SOC 2, Microsoft 365 SOC 2 / ISO 27001 / HIPAA-eligible). We maintain the current subprocessor list on the Privacy Policy page.
All primary data storage is in the United States. AWS S3 buckets are configured to US regions only. Airtable and Noloco operate from US infrastructure. If you operate facilities outside the US and have a data residency requirement, talk to us before signing; we are honest about what we can and cannot accommodate.
Customer data is backed up continuously by Airtable, Noloco, and AWS S3 per each provider’s standard policies. On a deletion event, your data ages out of backups per the subprocessor’s retention schedule (typically 30 to 90 days). On request after termination, we will export your data in a portable format (CSV or equivalent) before deletion. We do not yet operate an independent off-vendor backup pipeline.
Customer-data tables maintain an audit log of who created, modified, or deleted records, with timestamps. Audit log retention is 24 months on the Starter tier and indefinite on Operator and Regional tiers while the subscription is active. The log is read-only from the customer portal and exportable on request.
If we become aware of a security incident affecting your data, we will notify you without undue delay and in compliance with applicable law. Pre-launch we do not yet commit to a specific notification SLA in hours; that will be defined in our Data Processing Addendum as we onboard customers in regulated industries that require it.
If you find a vulnerability in HardPan, please report it to [email protected]. Include enough detail to reproduce. We will acknowledge within two business days. We do not yet operate a formal bug bounty program but we are grateful to researchers who report responsibly and will recognize them publicly with permission.
HardPan is a pre-launch product (May 2026). We do not yet hold SOC 2, ISO 27001, or HIPAA certifications. Our 2026 - 2027 plan: SOC 2 Type I within 12 months of first paying customer; SOC 2 Type II 12 months after that; ISO 27001 evaluated based on customer demand. HIPAA is not applicable - we do not process protected health information. If your procurement process requires a security questionnaire or SIG Lite, contact us at [email protected] and we will complete it honestly, including marking what is not yet in place.
Pre-launch we have not yet engaged a third-party penetration testing firm. The plan is annual external testing starting within 6 months of first paying customer, with summary findings available to customers under NDA.
For security questions, vulnerability reports, or procurement questionnaires:
25 Fathoms, LLC dba HardPan™
Security contact: [email protected]
General contact: [email protected]
Send it over. We’ll complete it honestly, including what isn’t in place yet.