Trust & security

Architecture you can inspect.

TheGonch is early. We document the controls that exist today, the boundaries of the current architecture, and what is not yet in place so firms can evaluate the platform accurately.

Request path · where each boundary is enforcedSelect a layer
Row-level access
Row-level security policies

Database policies restrict the rows a signed-in user can read or change. Privileged server operations use separate authorization checks.

Controls at this layer
Row-level security on tenant data
Role evaluated in policy, not only in the interface
This is the control most worth reviewing in a technical session. We will walk through the policies directly.
01 · Current controls

What is in place today.

Each item below is implemented in the current platform. Where a control is provided by an infrastructure provider rather than by TheGonch directly, the row says so.

ControlImplementationProvided by
Row-level securityDatabase policies restrict the rows a signed-in user can read or change. Privileged server operations use separate authorization checks.TheGonch
Tenant isolationEach firm is a tenant. Its operating data is scoped through advisor, team and organization relationships, with access enforced by database policies.TheGonch
Role-based accessAdvisor, manager and administrator roles. Advisors work in their own practice; managers oversee the teams they manage. Privileged administration is restricted to the platform owner. Access is checked in database policies and server-side guards.TheGonch
Encryption in transitAll traffic between the browser, the application and the database is over TLS.Platform
Encryption at restStored data is encrypted at rest by the infrastructure providers that host it. TheGonch does not operate its own key management.Providers
Administrative action loggingPrivileged account and team actions performed through the platform’s audited administration routes are logged. This is not yet a full, exportable audit trail of all user activity.TheGonch
US-hosted primary databaseThe primary database is hosted in the United States (AWS us-east-1, Northern Virginia). This describes the database only; see sub-processors for other providers.Providers
Firm-owned dataOperating data entered by a firm and its advisors belongs to the firm. TheGonch processes it to provide the service and does not use it for advertising or sell it.TheGonch
02 · Architecture & providers

A small, inspectable stack.

TheGonch runs on a small number of well-known infrastructure providers. Processing regions for providers other than the database are listed on the sub-processors page where confirmed, and marked where confirmation is still pending.

Full sub-processor list →
Application hosting
Vercel
Serves the web application and its server-side functions. Handles TLS termination.
Database & auth
Supabase
Managed Postgres with row-level security, authentication and storage. Hosts the primary database.
Underlying cloud
AWS us-east-1
Northern Virginia. The region in which the Supabase-managed primary database runs.
03 · Security status

What is not yet in place.

Firms should evaluate TheGonch knowing this list. No dates are given because none are committed. Status is updated as items change.

ItemCurrent positionStatus
SOC 2No SOC 2 report exists. TheGonch has not begun a SOC 2 audit.Not yet implemented
ISO 27001Not certified and not in progress.Not yet implemented
Independent penetration testingNo third-party penetration test has been performed. Internal review only.Not yet implemented
SAML SSO / SCIMNot available. Authentication uses the platform’s own identity service; accounts are provisioned and approved during deployment.Not yet implemented
Retention and deletion proceduresDeletion and export are handled on request from the firm. A documented, self-serve retention policy does not yet exist.Partial
Audit loggingPrivileged account and team actions performed through the platform’s audited administration routes are logged. Full user-activity audit trails and log export are not yet available.Partial
Monitoring and SLAApplication and provider monitoring is in place. No contractual uptime SLA is offered at this stage.Partial
Bulk data exportAvailable on request, handled by TheGonch. Self-serve bulk export is not yet in the product.Partial
Encryption in transit and at restTLS for all traffic; at-rest encryption by the infrastructure providers.Implemented
Tenant isolation and row-level securityEnforced in the database for all tenant data.Implemented
04 · Technical review

Talk to the people who built it.

Compliance, technology and security teams can review the platform directly with the engineers responsible for it. Questions are answered by the people who can change the answer.

Request a technical review
Available for review
Architecture
Providers
Data model
Current controls
Tenant isolation
Access boundaries
Roles
Items not yet in place