Back to home
Trust & Security
Live · verifiable now

Built for InfoSec from day one.

Don't take our word for it. Click Re-run live check below — every claim on this page is verified against the live API in under one second.

All security checks passed

4 of 4 guarantees verified · ran in 154ms · evaluated 5/28/2026, 7:59:25 PM

4/4

live

Security headers + tenant watermark active

security_middlewares_mounted

Per-org collection naming enforced

tenant_db_partitioning

JWT validation rejects tampered tokens

jwt_signature_validation

Stripe key sourced from env, never user input

stripe_key_env_only

mode: test · key type: secret

Uptime & status
Service availability — last 30 / 90 days.
operational

99.95%

30-day uptime

99.92%

90-day uptime

0 incidents in the last 30 days · health pings today: 0

Wire-level proof
The headers your browser just received.

Verify yourself: curl -I https://cartieai.com/api/trust/live-check

Compliance & certification roadmap

Where we are, where we're going, and the controls already in place. Truthful framing — we don't claim certifications we don't have.

LIVE

SOC 2-aligned controls

Following SOC 2 Type I controls (stateless cloud creds · encrypted-at-rest · JWT auth with rotation · audit log on every privileged action). Documentation generated from the open-source strongdm/comply toolkit.

LIVE

GDPR-aligned data handling

30-day deletion on account close · per-tenant DEK · DPA available on request.

LIVE

Multi-tenant isolation

Physical per-org MongoDB collections · X-CARTIE-Org-ID watermark on every response · 60+ leak_guard tests on every CI run.

PLANNED

Compliance automation platform

Evaluating Drata and Vanta (industry standards) for evidence automation. Adoption begins at customer #25 — qualifying for the startup program in either at that scale.

PLANNED

SOC 2 Type II audit

CPA auditor selection (likely Insight Assurance, Prescient, or Sensiba — startup-friendly $7–12K range) begins at customer #25. Typical observation window 6–12 months.

PLANNED

ISO 27001

Post-Series-A roadmap once SOC 2 Type II is in hand.

PLANNED

HIPAA-aligned BAA

On request for healthcare customers post-Series-A.

Most-asked questions

Answers we wish came pre-packaged with every InfoSec questionnaire.

No — and we don't want it. We use Stripe Restricted Keys with read-only scope on Customer / Subscription / Invoice. They cannot refund, charge, or access cards. Revocable in 5 seconds.

Four equally-valid integration paths:

  • SMB / Startup: Stripe Restricted Key, read-only.
  • Mid-market / Series B: Stripe Connect OAuth — customer clicks "Connect Stripe", approves on stripe.com, never pastes a key.
  • Enterprise / regulated: Run our exporter inside your VPC. Only aggregated, hashed identifiers leave your network.
  • Paranoid: Drop a Stripe export CSV once a month.

Need our SIG-Lite or a signed DPA?

We respond to InfoSec questionnaires within 1 business day.

Last evaluated: 5/28/2026, 7:59:25 PM · Back to CARTIE AI

We value your privacy. Cookies help us improve your experience. Learn more

Install CARTIE AI

Add to your home screen for quick access and offline support