NextStage

Security

Built so the work stays yours.

A founder's strategy, customer interviews, financials, and pitch are some of the most sensitive material a company holds. NextStage treats it that way at every layer — encryption in transit, encryption at rest, audited infrastructure, peer-reviewed code, and access controls enforced at the database.

Six commitments. None of them optional.

01

Encrypted in transit

All traffic between your browser, our servers, our database, and every third-party we touch is encrypted with TLS 1.2 or higher. HTTPS-only by default. WebSocket connections use WSS.

02

Encrypted at rest

Every row of your data — the loadout slots, vault documents, generated artifacts, chat history, evidence library — is encrypted at rest with AES-256. Storage objects are encrypted. Backups are encrypted.

03

Audited infrastructure

NextStage is built on SOC 2 Type II compliant providers end-to-end. Every layer your data touches — database, hosting, models, compute, observability, email — is independently audited.

04

Secure development

Every code change passes peer review, an automated test suite, and continuous dependency vulnerability scanning before it merges. Production deploys are immutable. Secrets are never committed.

05

Backups + recovery

Point-in-time recovery on the primary database. Cross-region backups stored separately from production infrastructure. Backups are encrypted and access-restricted.

06

Access controlled

Role-based permissions enforced at the database level via Row-Level Security. Coaches see what they should. Cofounders see what they should. Nothing leaks across boundaries.

Audited infrastructure

Every layer your data touches is independently audited.

NextStage is composed of a small set of providers, each with their own SOC 2 Type II attestation. Your data flows through them; their audits cover them.

ProviderRoleAttestation
SupabaseDatabase, storage, auth, realtimeSOC 2 Type II
VercelHosting, edge network, deploymentsSOC 2 Type II
AnthropicClaude — language modelSOC 2 Type II
OpenAIWhisper, fallback embeddingsSOC 2 Type II
ModalSelf-hosted NLI compute (MiniCheck)SOC 2 Type II
ResendTransactional emailSOC 2 Type II
SentryError monitoringSOC 2 Type II

Compliance posture

Where we are. Where we're going.

Today

Every claim on this page is true now. Encryption is on by default. Backups are running. Code review and dependency scanning are part of every merge. The infrastructure NextStage runs on is independently audited at SOC 2 Type II.

In progress

NextStage's own SOC 2 Type II attestation is being prepared. The application layer — our policies, access controls, and incident response — is in audit. Once attested we'll publish the report under NDA on request.

Annually

Independent penetration testing on the application surface. Findings remediated and re-tested before the engagement closes.

Report a vulnerability

Found something? Tell us first.

We treat security reports seriously and respond within one business day. Email security@nextstage.co with steps to reproduce. Coordinated disclosure honored. We don't pursue researchers acting in good faith.

Ship the work somewhere it stays yours.

Encryption, audited infrastructure, and access controls are the floor. The work is what compounds.