Security

    Security at Pharos

    Where your data is hosted, how it is protected and which services process it. This page describes how Pharos runs today; the same measures are the commitments in our Data Processing Agreement.

    At a glance

    Primary database
    Supabase (managed PostgreSQL), AWS us-east-1, N. Virginia, United States
    Web hosting
    Vercel, served over HTTPS from its global edge network
    Encryption
    TLS 1.2 or higher in transit; encrypted at rest
    Customer isolation
    Row Level Security on every customer-scoped table
    Certifications
    None held today (no SOC 2 or ISO 27001)
    Report an issue
    support@heypharos.com

    Hosting

    Pharos's primary database, authentication and file storage run on Supabase's managed platform, in the AWS us-east-1 region (N. Virginia, United States). There is no regional hosting outside the United States. The website and the app are served by Vercel.

    Encryption

    • In transit: every customer-facing endpoint is HTTPS only, using TLS 1.2 or higher.
    • At rest: data is encrypted by the providers that store it (Supabase for the database and files, Stripe for payment data). Pharos never sees or stores full card numbers.
    • Secrets and API keys are kept in managed secret stores, never in source code.

    Access control

    • Row Level Security (RLS) is applied to every customer-scoped database table, so each workspace can read only its own brands and data.
    • Inside a workspace, members have roles, and access follows them.
    • Access to production systems is limited to the people who need it, protected by multi-factor authentication, logged and reviewed.
    • Changes to production go through code review and automated checks.

    AI providers

    To measure your visibility, Pharos sends the questions you track (which include your brand and competitor names) to AI platforms and to the data-collection services that query them. We do not use your account data, prompts or results to train any AI model, and where a provider offers zero-retention or no-training options for API traffic, we use them.

    Sub-processors

    The core services are Supabase (database and authentication), Vercel (hosting), Stripe (payments) and Resend (email), plus the AI platforms and data-collection services that produce your results. The full list, with what each one does and where it is based, is on the sub-processors page.

    Backups and incidents

    • The database is backed up at least daily.
    • If a breach affects your personal data, we notify you without undue delay. Customers with a Data Processing Agreement are notified within 72 hours of confirmation.
    • Data is deleted within 30 days of account termination, except where the law requires us to keep it (invoices, for example). Details are in the privacy policy and the Data Processing Agreement.

    Certifications and questionnaires

    Pharos does not currently hold a third-party security certification such as SOC 2 or ISO 27001. A Data Processing Agreement and answers to your security questionnaire are available on request from sales@heypharos.com.

    Reporting a vulnerability

    If you believe you have found a security issue in Pharos, email support@heypharos.com with "Security" in the subject, the steps to reproduce it and the impact you observed. Please give us reasonable time to fix it before sharing it publicly, and do not access, change or delete data that is not yours while testing. We will acknowledge your report and keep you updated until it is resolved.