papertail papertailTM

Security

Effective Date: February 12, 2026 Last Updated: February 12, 2026

Architecture

papertail runs on Google Cloud Platform:

There are no self-managed servers. All infrastructure is managed by Google Cloud.

Authentication

Encryption

Access Control

Data Minimization

Vulnerability Management

Dependency Scanning

Patching

Severity Response Remediation
Critical (CVSS 9.0+) 24 hours 7 days
High (CVSS 7.0-8.9) 48 hours 14 days
Medium (CVSS 4.0-6.9) 1 week 30 days
Low (CVSS 0.1-3.9) 2 weeks 90 days

Code Review

Incident Response

In the event of a suspected compromise:

  1. Revoke affected Plaid access tokens via Plaid Dashboard
  2. Rotate Cloud Run environment secrets
  3. Review Cloud Run and Firestore audit logs
  4. Notify affected users via push notification and email

Data Retention and Deletion

See our Privacy Policy for full details on what data is collected, how long it is retained, and how to delete it.

Third-Party Services

Service Purpose Security
Plaid Bank data access SOC 2 Type II, encrypts all data in transit and at rest
Google Cloud / Firebase Hosting, database, auth, notifications SOC 2, ISO 27001, encrypts all data at rest
Apple App Store iOS app distribution and subscriptions App Review, sandboxed execution
Google Play Store Android app distribution and subscriptions Play Protect, app signing

papertail does not use any analytics SDKs, advertising networks, or third-party tracking.

Contact

For security concerns, email support@papertail.app.