SYSTEM:SECURITY_OVERVIEW
Security & Privacy
Resurgo is built on security-first infrastructure. Here's exactly how we protect your data.
Authentication
SSO / OAuth
Google, GitHub, and more — no password required if you prefer
Multi-Factor Auth
TOTP and SMS 2FA available on all accounts
Session management
Device-level session control; revoke access from any device
Brute-force protection
Rate-limiting and lockouts on failed attempts
JWT tokens
Short-lived, signed tokens; auto-rotated on every request
Data Encryption
TLS 1.3
All traffic between client and server uses TLS 1.3
At-rest encryption
AES-256 encryption for all data stored in Convex databases
Database isolation
Each deployment runs in isolated Convex infrastructure
No raw password storage
Passwords are never stored — authentication handled entirely by Clerk
Secure file uploads
Files stored in Convex storage with signed URL access
Data Privacy
Data minimisation
We only collect data required to deliver core features
No selling data
Your personal data is never sold or shared with advertisers
User-controlled deletion
Delete your account and all associated data at any time from Settings
Export your data
Request a full data export in JSON format at any time
Third-party integrations
Only Clerk (auth), Convex (database), and Vercel (hosting) have limited access
Compliance & Standards
GDPR
Fully compliant with EU General Data Protection Regulation
CCPA
California Consumer Privacy Act rights honoured for all users
Data Processing Agreements
DPAs available for enterprise customers on request
Audit logging
All sensitive actions are logged with timestamps and user ID
Vulnerability disclosure
Responsible disclosure: security@resurgo.life
Infrastructure
Vercel Edge Network
Global CDN with automatic DDoS mitigation
Convex cloud
SOC 2 Type II certified real-time database infrastructure
Zero-downtime deploys
Atomic deployments — no maintenance windows
Availability SLA
99.9% availability target with automated monitoring and alerting
Disaster recovery
Automated backups; point-in-time recovery available
SECURITY_CONTACT
Found a vulnerability? We take security reports seriously and will respond within 48 hours.
> RESPONSIBLE_DISCLOSURE
security@resurgo.life