Skip to content
Security

Your data is secure

Aceframe is built on enterprise-grade infrastructure with encryption, access controls, and compliance baked in from day one.

TLS 1.3

Encryption in transit

AES-256

Encryption at rest

SOC 2

Certified infrastructure

PCI Level 1

Payment security

How we protect your data

Encryption in transit

All connections are secured with TLS 1.3 encryption. Data is always encrypted between your browser and our servers.

Encryption at rest

All stored data is encrypted with AES-256. Passwords are hashed with bcrypt using per-user salts.

SOC 2 certified infrastructure

Hosted on Vercel (SOC 2 Type II certified) with Vercel Postgres. Automatic failover and redundancy built in.

PCI Level 1 payments

All payments processed by Stripe (PCI DSS Level 1). Card data never touches Aceframe servers.

Workspace access controls

Role-based permissions (owner, admin, member, viewer) with email-verified invitations. Granular control over who sees what.

Secure authentication

Session-based auth via NextAuth with Google OAuth or email/password login. No shared passwords, no insecure tokens.

Data handling

Data residency

All data is stored in US-East data centres. Enterprise customers can discuss specific residency requirements.

Data retention

Your data is retained while your account is active. Deleted accounts and demos are permanently removed within 30 days.

GDPR compliant

We only collect data necessary to provide the service. Users can request data export or deletion at any time.

Subprocessors

We use a small number of trusted third-party services to operate Aceframe.

Provider

Purpose

Location

Vercel

Application hosting and serverless compute

US

Vercel Postgres

Primary database (encrypted at rest)

US-East

Vercel Blob

File and media storage

US

Stripe

Payment processing (PCI Level 1)

US

Resend

Transactional email delivery

US

Anthropic

AI features (annotations, viewer Q&A)

US

Responsible disclosure

If you discover a security vulnerability, please report it responsibly. We take all reports seriously and will respond promptly.

Ready to create your first demo?

Sign up for free and launch your first interactive demo in minutes.