Trust Center

Odin handles the most confidential documents a firm owns. This page is the whole posture in two honest lists: what is in place today, and what is committed — never a claim in between.

Why firms trust Odin with deal data

  • No model training on customer data.Odin's AI calls the Anthropic API, which does not train on API inputs.
  • Compartmented Mode. A deal can be walled off so firm-wide AI features never read it.
  • Per-deal scoping. Admins control which members can reach which deals — at invite time, org-wide, or deal by deal.
  • Append-only audit trail. Sensitive actions are recorded with actor, IP, and user agent.

In place today

ControlWhat it means
Transport encryptionTLS 1.2+ with HSTS on every customer-facing endpoint.
Encryption at restDatabase and object storage encrypted at rest by our infrastructure providers (Supabase, Vercel), AES-256 by default.
Access controlRole-based permissions checked server-side on every API route, with Postgres row-level security as a second line of defense. Optional per-deal scoping restricts which members reach a given deal.
Multi-factor authenticationAvailable on every account via Clerk; workspace admins can require it for their org.
Audit trailAppend-only audit log of sensitive actions with actor, IP address, and user agent — never updated or deleted by application code.
Rate limitingPer-org request rate limits on the API (Upstash).
Change managementSix required CI checks on every change (typecheck, lint, tests, build, security guards, dependency audit); production deploys only from the protected main branch; commit-time secret scanning; Dependabot CVE monitoring.
AI spend & usage controlsPer-org metering on every AI call, monthly caps with automated spike alerts, and per-user ceilings.

Committed — not yet in place

Listed separately on purpose: none of the items below appear anywhere on this site as a current capability, and each moves up only when it is real.

  • SOC 2 Type 1. We engage an auditor as customer demand warrants, and claim it only when the audit begins.
  • Web application firewall. Platform WAF evaluation is scheduled on the security roadmap.
  • Static analysis (CodeQL / GHAS). On the security roadmap behind the CI gates already in place.
  • Third-party penetration test. Ahead of the SOC 2 engagement.
  • MFA enforced by default. Org-required enrollment with step-up verification on sensitive admin actions.

Continuity & incident readiness

  • Incident response. A written IR plan defines severity levels, roles, and customer-notification commitments; it is exercised by walkthrough. Security contact below.
  • Backups & recovery. Daily automated database backups via Supabase, with documented recovery objectives in our BC/DR plan.
  • Policy set. An information-security policy set and a maintained risk register govern engineering practice; public-safe summaries are available to customers under NDA on request.

Vendors & data flow

10 sub-processors touch customer data, each listed with role and region on the sub-processor register. The full picture — what data lives where, and why — is on the Security page, alongside our DPA, Privacy Policy, and Terms.

Report a security issue

Email security@txnhub.app. We acknowledge within one business day. We do not yet run a formal bounty program.

Last updated: 2026-08-11