Security

Sub-processors

FixGrid uses the third-party sub-processors below to deliver the service. Each is a reputable provider that maintains its own security program, with current attestations published on its trust page.

Current sub-processors

Who processes data, and why.

PurposeApplication hosting (compute) + managed PostgreSQL database
DataAll FixGrid application + customer data at rest (encrypted AES-256)
LocationUnited States
AttestationsSOC 2 Type II
PurposeCDN, WAF, DDoS protection, TLS termination, Turnstile bot protection, R2 object storage
DataAll inbound traffic; stored files (photos, documents, reports) in R2
LocationGlobal edge (US configuration)
AttestationsSOC 2 Type II, ISO 27001:2022
PurposeSubscription billing + payment processing
DataPayment/card data (held entirely by Stripe — never stored by FixGrid); subscription metadata
LocationUnited States / global
AttestationsPCI DSS Level 1, SOC 1/2
PurposeTransactional email delivery (invites, notifications, password resets)
DataRecipient email address + message content
LocationUnited States
AttestationsSOC 2 Type II, GDPR, EU-US Data Privacy Framework
PurposeAI features (Grid Zenith narratives, AI-assisted intelligence)
DataAggregated property/portfolio metrics + operational text for narrative generation. No payment data. No raw resident PII required. Per Anthropic's commercial API terms, inputs/outputs are not used to train models.
LocationUnited States
AttestationsSOC 2 Type II, ISO 27001:2022, ISO 42001:2023
Notes

How we manage sub-processors.

FixGrid does not store cardholder data — payment data is handled exclusively by Stripe, a PCI DSS Level 1 provider.
We notify customers of any new sub-processor (or replacement of an existing one that processes customer data) before it begins processing, so customers may raise concerns.
New sub-processors are evaluated for security posture before adoption, and each is reviewed at least annually.
Underlying infrastructure providers used by our sub-processors are covered transitively by those sub-processors' own compliance programs.
Current as of June 21, 2026.
Questions

Need our DPA or a security review?

Contact [email protected]

See also our Responsible Disclosure Policy and Security overview.