Security
Our comprehensive security program is designed to protect your sensitive financial data at every layer of our stack.
Infrastructure & Hosting
- Hosted on enterprise-grade cloud infrastructure (such as AWS or GCP)
- Multi-region availability and automated backups
- Network isolation between production and corporate environments
- WAF + DDoS protection
Data Encryption
- AES-256 at rest (databases, file storage, backups)
- TLS 1.2+ in transit for all client connections and internal services
- Encryption keys managed via cloud provider's managed KMS
Access Control
- Role-based access control (RBAC) with least-privilege principle
- MFA required for all internal access to production
- SSO available for customers on enterprise plans
- Access logs retained for at least 12 months and reviewed regularly
Application Security
- Secure SDLC with peer code review
- Automated dependency vulnerability scanning
- Static and dynamic security testing in CI/CD
- Multi-tenant architecture with strict tenant isolation
Operational Security
- Documented incident response plan with defined escalation
- Periodic vulnerability scanning and penetration testing (frequency disclosed under NDA)
- Disaster recovery and business continuity procedures with testing
- Security and privacy training for all personnel on hire and annually
Personnel
- Background checks where legally permitted for personnel with production access
- Confidentiality agreements signed by all staff and contractors
Privacy
We believe privacy is a fundamental right. Our practices are built on transparency, minimization, and user control.
You Own Your Data
- Customer Data is owned by the customer
- We process it only to provide the Service per documented instructions
- Easy export and deletion at any time
Privacy by Design
- Data minimization — we only collect what we need
- Purpose limitation — we only use it for stated purposes
- Transparency — clear policies, plain language
- User rights honored across all major jurisdictions
Global Compliance
- GDPR & UK GDPR — SCCs + UK IDTA for international transfers
- CCPA / CPRA — Service Provider commitments; we do NOT sell or share personal information
- Other US State Laws — VCDPA, CPA, CTDPA, UCPA, TDPSA
- Swiss FADP — Swiss-amended SCCs in place
Your Rights
- Access, correct, delete, port, restrict, and object to processing
- Withdraw consent at any time
- Lodge a complaint with your supervisory authority
- Contact: support@getrecurved.com
AI Responsibility
AI sits at the heart of what we do — and we take its responsible use seriously.
How We Use AI
- Recurved uses AI/ML to forecast revenue, model scenarios, and benchmark against peers
- Outputs are generated from your business's data, the structure of forecasting models, and aggregated insights from anonymized industry data
Model Transparency
- Models are continuously evaluated for accuracy and bias
- Customers have access to assumptions and methodology documentation in the product
- We disclose material changes to AI behavior in release notes
What We Do NOT Do
- ❌ We do not use your identifiable Customer Data to train AI models that are shared across customers
- ❌ We do not sell or share your data with AI providers for their own training
- ❌ We do not use your data for advertising
What We DO Do
- ✅ We use aggregated, de-identified data to improve our models and benchmarks
- ✅ You can request human review of any automated decision that significantly affects you (GDPR Art. 22)
- ✅ Our AI Outputs are clearly labeled as forecasts — they are decision-support tools, not financial advice
Compliance & Certifications
Certification artifacts and audit reports are available to customers and prospects under NDA. Email support@getrecurved.com to request.
Sub-processors
Recurved engages third-party service providers (sub-processors) to assist in providing our services. We strictly evaluate all sub-processors for security, privacy, and confidentiality practices.
We maintain a current list of all sub-processors who may process Customer Data on our behalf.
Customers may subscribe to email notifications of any changes to our sub-processor list. Email support@getrecurved.com to subscribe.
Data Residency & Incident Management
Data Residency & Transfers
- Primary processing in the United States
- International transfers governed by EU Standard Contractual Clauses, UK IDTA, and Swiss amendments
- Transfer impact assessments performed; supplementary measures in place (encryption, access logging, government-request scrutiny)
Incident Response & Breach Notification
- 24/7 monitoring and on-call incident response
- Documented response procedures
- Customer notification within 72 hours of confirmed Personal Data Breach affecting Customer Data
- Post-incident reports provided to affected customers
Responsible Disclosure & Uptime
Responsible Disclosure
- We welcome responsible disclosure from security researchers
- Email: support@getrecurved.com with subject "Security Disclosure"
- We commit to acknowledge reports within 3 business days
- We will not pursue legal action against researchers acting in good faith under our responsible disclosure guidelines
Status & Uptime
We are committed to high availability and transparent reporting of system performance.
Documents & Resources
- 📄 Privacy Policy
- 📜 Terms of Service
- 🍪 Cookie Notice
- 🤝 Data Processing Addendum (DPA)
- 📋 Sub-processor List
- 🛡️ Security Overview (PDF — coming soon)
- 📑 SOC 2 Report (available under NDA)
- 📝 CAIQ / Security Questionnaire (available under NDA)
Contact Information
- Privacy Questions: support@getrecurved.com
- Security Questions: support@getrecurved.com (Please include "Security" in the subject line)
- Sales & Enterprise Questionnaires: support@getrecurved.com
- Mailing Address: 2803 Philadelphia Pike, Suite B #288, Claymont, DE 19703
Information on this page is intended to provide general transparency about Recurved's security and privacy practices. Specific contractual commitments are set forth in the Terms of Service, Data Processing Addendum, and Order Form between Recurved and each customer.
© 2026 Recurved, Inc. • Effective: January 1, 2026 • Last Updated: June 10, 2026