Effective Date: April 1, 2026 · Last Updated: April 1, 2026
Courtasy (“we,” “us,” or “our”) is committed to maintaining the security, integrity, and confidentiality of all data processed through our Platform at https://courtasy.com. This Security Policy describes the technical and organizational measures we implement to protect Customer Data and Platform infrastructure.
This policy applies to Courtasy's employees, contractors, sub-processors, and the systems that support the delivery of our services.
The Platform is hosted on Amazon Web Services (AWS):
AWS maintains comprehensive certifications including ISO 27001, SOC 2 Type II, and PCI DSS Level 1.
| State | Standard |
|---|---|
| Data in Transit | TLS 1.2+ enforced for all communications |
| Data at Rest | AES-256 encryption via AWS-managed keys |
| Database | Encrypted at the storage layer |
| Backups | Encrypted with the same standards as production data |
| Payment Data | Tokenized and managed by Stripe — raw card data never touches Courtasy servers |
All user authentication is handled via Clerk, which provides secure session management, multi-factor authentication (MFA), and OAuth 2.0. Customers are strongly encouraged to enforce MFA for all Authorized Users.
We conduct due diligence on all sub-processors and require that they maintain security standards consistent with or exceeding industry norms.
| Provider | Role | Security Certifications |
|---|---|---|
| AWS | Cloud infrastructure | ISO 27001, SOC 2, PCI DSS |
| Stripe | Payment processing | PCI DSS Level 1 |
| Clerk | Authentication | SOC 2 Type II |
| Resend | Email delivery | SOC 2 |
| Analytics | ISO 27001, SOC 2 |
We maintain a documented Incident Response Plan. Upon detection of a security incident, our team follows a structured process: Identify → Contain → Eradicate → Recover → Review.
In the event of a confirmed personal data breach, Courtasy will:
Our status page at status.courtasy.com provides real-time updates during any service incident.
The Platform is designed to support Customer compliance with applicable data protection laws. We conduct internal security reviews at least annually. Customers may request a summary of our security practices or a completed security questionnaire by contacting legal@courtasy.com.
We encourage responsible disclosure of security vulnerabilities. If you discover a potential security issue, please email legal@courtasy.com with the subject line “Security Vulnerability Report.” Include a description of the issue, steps to reproduce, and potential impact. Do not publicly disclose the vulnerability until we have had reasonable opportunity to investigate and remediate.
We may update this Security Policy as our practices evolve. Material changes will be communicated to Customers via email or in-platform notice.
We're happy to complete a vendor security questionnaire or speak directly with your security team.
Contact our security team