Concierge Pilot
← Back to site

Information Security Policy

LAST UPDATED: MAY 3, 2026 · VERSION 1.0

On this page

Scope Roles Classification Access control Encryption Network Vulnerability mgmt Secure SDLC Incident response Backup Subprocessors Training Retention Autopilot Review Contact

1. Scope and purpose

This Information Security Policy applies to all systems, data, and personnel of Custom AI Apps LLC ("the Company"), operator of Concierge Pilot, Texicurean OS, Arpejo, Jigger, and Kitchen Cost Tracker (collectively, the "Services"). It covers data we collect from end users (restaurant owners, fans, artists, and venue staff), data we receive from third-party APIs (Plaid, Stripe, Google, Spotify, Ticketmaster), and data created by users inside the Services.

The purpose of this policy is to (a) protect the confidentiality, integrity, and availability of customer data, (b) comply with applicable privacy laws (including the CCPA / CPRA), (c) meet contractual obligations with subprocessors such as Plaid and Stripe, and (d) maintain a posture proportionate to the size and risk profile of the business.

2. Roles and responsibilities

The Company is a small business with a single technical lead.

3. Data classification

ClassExamplesHandling
RestrictedPlaid bank tokens, Stripe secret keys, Supabase service role keys, customer payment card last-4 + tokens, bank routing/account numbersStored only in encrypted secret stores (Supabase Vault, Stripe-tokenized references, Plaid-managed access tokens). Never logged, never transmitted in plain text, never shared with humans by email or chat.
SensitiveEnd-user names, emails, phone numbers, business addresses, transaction history, employee schedule data, fan profile data, photo uploadsStored encrypted at rest. Read access scoped to the owning business via row-level security. CSV export available only to authenticated business administrators.
InternalAggregate metrics, AI prompt logs (without personal data), system telemetryStored in standard Postgres tables, retained per Section 13.
PublicMarketing site copy, public llms.txt and agents.html, published Arpejo eventsNo restriction.

4. Access control

Access to production systems and data follows the principle of least privilege.

5. Encryption

6. Network and infrastructure security

7. Vulnerability management

8. Secure software development lifecycle

9. Incident response

The Company maintains a documented incident response process tuned to its size:

10. Backup and disaster recovery

11. Subprocessors

The Company uses the following subprocessors, each bound by their own security and privacy commitments:

SubprocessorPurposeCompliance
StripePayment processing, Connect, refundsPCI DSS Level 1, SOC 2 Type II
PlaidBank connectivitySOC 2 Type II, ISO 27001
SupabasePostgres, authentication, storage, edge functionsSOC 2 Type II, HIPAA-eligible
NetlifyWeb hostingSOC 2 Type II
OpenAIAI inferenceSOC 2 Type II
AnthropicAI inferenceSOC 2 Type II
ResendTransactional emailSOC 2 Type II
Twilio / VapiSMS and voiceSOC 2 Type II, HIPAA-eligible
Google CloudPlaces API, Maps, GeminiSOC 1/2/3, ISO 27001

The Information Security Lead reviews the list quarterly. Adding a new subprocessor requires verifying the provider has a published SOC 2 or equivalent attestation, a public privacy policy, and a documented data-processing agreement (DPA). Removing a subprocessor requires confirming all customer data is purged from their systems.

12. Training and personnel

The Company has one technical operator (the Information Security Lead). At onboarding, every new operator (none currently planned) would be required to:

The Information Security Lead reviews this policy and the threat landscape at least quarterly.

13. Data retention and deletion

The Company retains customer data only as long as necessary to provide the Services or to comply with legal obligations.

Customers may request deletion of their data at any time by emailing [email protected]. See the Privacy Policy for the full deletion procedure and the rights of California residents under CCPA / CPRA.

14. Autopilot — agentic commerce safeguards

Concierge Pilot offers an optional add-on called Autopilot that automates routine vendor-replenishment for our customers. Because Autopilot moves money on the customer's behalf, it is governed by the following safeguards.

15. Policy review and version control

This policy is reviewed at least annually by the Information Security Lead, and reissued whenever there is a material change to the Services, the subprocessor list, the legal landscape, or a contractual obligation. Material changes are noted in the version history below.

16. Contact

Questions about this policy, security disclosures, or compliance follow-ups:

Custom AI Apps LLC
Attn: Information Security
4814 Arc Bend Road
Midlothian, TX 76065
Email: [email protected]