Last updated: 2026.08.18

This page describes how KillDebt protects customer data across its services, including KillDebt for Professionals. It is written for the people who evaluate vendors: IT teams, compliance officers, and counsel. For contractual commitments, see the Data Processing Agreement.

Architecture in one paragraph

KillDebt runs on managed cloud infrastructure: application hosting and delivery on Vercel, data on Supabase (AWS), payments exclusively through Stripe. Enterprise customer data lives in a dedicated database, physically separate from the consumer product. The Professional research tools are read-only — research queries go out, cited answers come back. We never access your case-management systems, and your client files never need to enter our systems to use the research service.

Encryption

  • In transit: TLS 1.2 or higher on every connection.

  • At rest: AES-256 across databases and file storage.

  • Payment cards: processed and stored exclusively by Stripe (PCI DSS Level 1). KillDebt never receives card numbers.

Data isolation

  • Enterprise organizations use a dedicated database project, separate from the consumer platform.

  • Access requires per-seat authentication. Credentials are individual; accounts are never shared.

  • All service endpoints are rate-limited.

Access control

  • Access to production systems within KillDebt is role-restricted, limited to named individuals, protected by multi-factor authentication, and logged.

  • KillDebt personnel do not review customer query content except as necessary for security, abuse prevention, support you request, or as required by law.

  • Your designated administrators can view seat and usage activity for your organization at any time.

Logging and monitoring

We log administrative actions, authentication events, file activity, and — for Professional customers — every research tool call, recorded to your organization's dedicated database. Logs support security investigation and give your administrators visibility into usage.

AI data handling

  • Nothing you submit is used to train AI models — ours or our providers'.

  • Model providers (OpenAI, Anthropic, Google, routed through the Vercel AI Gateway; Mistral for document OCR) process content transiently to generate responses, subject to API terms that prohibit training on inputs.

  • The full provider list, with each provider's role and certifications, is on the Subprocessor List.

Incident response

If we confirm a security incident affecting your data, we notify your designated contact without undue delay and no later than 72 hours after confirmation, with the nature of the incident, affected data and users as known, remediation steps, and a contact point.

Backups and continuity

Customer data is covered by encrypted backups with documented recovery procedures, on managed-provider infrastructure with provider-maintained redundancy.

Vulnerability management

Our platform surface is intentionally small: managed providers patch the infrastructure layer, and our development pipeline includes dependency monitoring. Critical dependency vulnerabilities are prioritized for immediate remediation.

Certifications

KillDebt is not independently SOC 2 certified at this time. Our infrastructure runs end-to-end on providers maintaining SOC 2 Type II attestations (Supabase/AWS, Vercel) and PCI DSS Level 1 (Stripe) — the full list is on the Subprocessor List. We complete customer security questionnaires promptly; send yours to support@killdebt.com.

Data residency

All customer data is stored and processed in the United States.

Questions

Security questions and reports: support@killdebt.com.