Trust Center
Security & Data
This page explains the safeguards and service providers used to operate Sullivan Pearl, along with important limits users should understand.
1. Authentication & Access
- External identity services: Authentication is handled through external identity services. Sullivan Pearl does not implement its own password store.
- Session validation: Protected requests validate authenticated sessions or access tokens before processing.
- Data scoping: Server-side routes use the authenticated user's identity when reading and writing user-owned records.
2. Infrastructure & Application Security
- Data in transit: Production access is configured for HTTPS. Authentication cookies are configured as secure, and the server applies standard HTTP security headers.
- Application controls: The server uses CORS controls, request-size limits, rate limiting, and sanitized error responses.
- Database services: Business data is stored using PostgreSQL and Supabase-backed managed database services.
- Document access: Uploaded and generated document storage is designed around private, user-scoped access rules.
3. Third-Party Services
- Billing processing: Subscription checkout and the billing portal are handled by Stripe. Sullivan Pearl does not directly store full payment-card numbers.
- AI processing: Content submitted to Pearl or other AI features is sent to third-party AI providers to generate requested outputs. Sullivan Pearl's AI operational logs are configured to omit prompts and secrets.
4. Risk & Data Sensitivity
While we use these standard controls, no system is completely risk-free. You should avoid entering unnecessary, highly sensitive client data (such as Social Security numbers, account numbers, or direct financial access details) into the platform.
5. Contact
For any questions or concerns regarding security, data handling, or privacy, please contact our support team at hello@sullivanpearl.com.