Trust & Compliance
Security at Blueberries
At Blueberries, security is foundational to everything we build. We protect your financial data with enterprise-grade infrastructure, rigorous access controls, and continuous compliance monitoring.
Last updated on April 08, 2026.
Security & Compliance certifications in progress
1. Compliance & Certifications
- SOC 2 Type II · In Progress
- GDPR · In Progress
- ISO 27001 · In Progress
- CSA STAR Level One · In Progress
- SSO · Supported
2. Infrastructure Security
- Hosted on AWS (us-east-1) with isolated VPC networking
- Continuous threat detection via AWS GuardDuty
- Full audit logging via AWS CloudTrail
- Real-time monitoring via AWS CloudWatch
- All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
3. Access Control
- Role-based access control (RBAC) enforced across all systems
- MFA required for all internal system access
- Least privilege principle applied to all infrastructure access
- Access reviews conducted periodically
4. Application Security
- Vulnerability scanning on all code repositories via GitHub Dependabot
- Branch protection enforced on all production repos
- Security reviews performed on all major releases
5. Data Protection
- Customer data encrypted at rest using AES-256
- Data in transit protected via TLS 1.2+
- Supabase (PostgreSQL) used for secure, isolated data storage
- Customer data deletion available upon request
6. Subprocessors
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services | Cloud infrastructure |
| Supabase | Database hosting |
| GitHub | Source code management |
| Deel | HR & payroll |
| Vanta | Compliance monitoring |
7. Incident Response
We maintain a formal incident response plan. In the event of a security incident affecting customer data, we commit to notifying affected customers within 72 hours in accordance with GDPR requirements.
8. Report a Vulnerability
If you discover a security vulnerability, please contact us at security@blueberries.app. We take all reports seriously and will respond within 48 hours.




