Security & Compliance Architecture
Operated by Skyfury LLC. How we protect contractor records, subcontractor certificates, and AI data flows.
Last Updated: September 30, 2026
Encryption at Rest & In Transit
All communications between your browser, subcontractor mobile devices, and COI Hound servers use strict TLS 1.3 encryption with automated SSL renewal. All stored documents and database records are encrypted at rest using AES-256.
Zero-Model-Training AI Policy
Our Vision OCR pipeline uses enterprise API endpoints with contractual guarantees: customer insurance certificates, policy numbers, and broker emails are NEVER used to train or refine public AI models. Data is processed transiently for extraction only.
Cryptographic Magic Link Tokens
Subcontractor upload links use high-entropy cryptographic tokens. Links cannot be guessed, indexed by search engines, or brute-forced. Uploads are scoped strictly to the designated subcontractor profile.
SOC 2 Compliant Infrastructure
COI Hound is hosted on enterprise-tier serverless cloud infrastructure provided by Vercel and Convex, featuring SOC 2 Type II certifications, 99.9% uptime SLAs, and multi-region automated redundancy.
1. Document Processing Architecture
When a trade subcontractor uploads an ACORD 25 certificate through their phone or computer:
- Direct Encrypted Ingestion: The PDF or image is securely transmitted over TLS 1.3 directly to our application processing endpoint.
- Digital Text Extraction: For digital PDFs, text layers are parsed in an isolated memory buffer without disk persistence.
- Vision OCR Analysis: Scanned files and smartphone photos are processed via high-resolution machine learning vision models. The extracted data is returned in structured JSON format.
- Encrypted Database Storage: The extracted policy figures, carrier names, and expiration dates are stored in Convex with automated indexing and contractor organization isolation.
2. Data Segregation & Multi-Tenancy
COI Hound enforces strict organizational data isolation:
- General Contractors can only access subcontractor records, certificates, and job sites linked directly to their organization ID;
- Database queries are scoped at the data access layer, preventing cross-tenant data leaks; and
- Subcontractor magic upload links provide write-only access to upload documents and view only their own company's specific compliance requirements.
3. Payment & Billing Security
All payments on COI Hound are processed through Stripe Inc., a certified PCI Service Provider Level 1 (the highest level of certification in the payments industry). Skyfury LLC never collects, processes, or stores your raw credit card numbers or CVV codes.
4. Vulnerability Disclosure & Incident Reporting
Skyfury LLC is committed to swift resolution of any discovered security vulnerabilities. If you believe you have discovered a vulnerability or security issue, please notify our team immediately: