Skip to content
MetrikData
How it worksCase studyCalculatorPricingDocumentationFAQContact
All solutionsMCA stacking detectionMCA underwriting softwareBank statement analysisStatement verificationMCA underwriting guideMCA glossary
For ISOsFor fundersFor brokersFor lendersFor underwritersNews & pressFeature RequestAbout
All comparisonsvs Ocrolusvs MoneyThumbvs DecisionLogicvs Onyx IQvs Heron Datavs LendSaaSvs Kaaj AI
Log inStart free
Trust

Security

Last updated July 11, 2026

MetrikData processes merchant bank statements that contain sensitive financial data. This page describes the technical controls, infrastructure, and policies that protect it.

1. Encryption

All data in transit between your browser and MetrikData is encrypted with TLS 1.3. Data at rest, including uploaded PDFs, extracted transaction records, and generated reports, is encrypted with AES-256. Encryption keys are managed by our infrastructure provider and are not accessible to MetrikData application code.

2. Infrastructure

MetrikData runs on Supabase (database, authentication, and object storage) and Vercel (application hosting). Supabase has completed SOC 2 Type II certification. Both providers operate in US-based data centers managed by AWS. MetrikData does not operate its own physical infrastructure.

3. Data residency

All uploaded statements, extracted data, and generated reports are stored and processed in US-based data centers (AWS US-East). No customer data is transferred to or stored in data centers outside the United States.

4. Workspace isolation

Every customer workspace is logically isolated. Database access is enforced through row-level security (RLS) policies, so one organization cannot read, query, or export another organization’s data. Uploaded PDFs are stored in private, per-workspace storage buckets with access gated by authenticated workspace membership.

5. Authentication and access control

User authentication is handled by Supabase Auth with secure session tokens. Workspace owners control member access through role-based permissions. Administrative access to production systems is restricted to authorized personnel, requires multi-factor authentication, and is logged.

6. Statement data handling

Uploaded bank statements are used exclusively to generate your analysis. MetrikData does not use uploaded statements to train machine learning models. Individual owner names are excluded from generated reports by design — reports surface transaction-level and cash-flow data, not personal identifiers.

You can delete individual cases, merchants, or your entire workspace at any time. When you delete a record, the underlying PDF and extracted data are removed from active systems promptly and purged from encrypted backups on a rolling schedule (backups are retained for a limited window for disaster recovery, then overwritten). Deleting your workspace removes all associated statements, extracted data, and reports.

7. Subprocessors

MetrikData relies on a limited set of subprocessors, each bound by contractual confidentiality and security obligations. The current list:

  • Supabase — database, authentication, and object storage (US)
  • Vercel — application hosting and edge network (US)
  • OpenAI — transaction classification (US)
  • Anthropic — transaction classification (US)
  • Stripe — payment processing (US)
  • Human-in-the-loop (HITL) — data processing and operational and technical support (US)

Each subprocessor accesses customer data only to perform its function and is contractually prohibited from using it for any other purpose. Uploaded statement content is never used to train third-party models. Human-in-the-loop (HITL) work — data processing and operational and technical support — is performed by personnel located in the United States; customer statement data is never sent outside the country. Changes to this list that materially affect data handling will be reflected on this page.

8. Incident response

MetrikData maintains an incident response process. In the event of a confirmed data breach affecting customer data, affected workspace owners will be notified within 72 hours of confirmation, with a description of the incident, the data involved, and remediation steps taken.

9. Backups and availability

Customer data is backed up automatically by our infrastructure providers. Backups are encrypted at rest with AES-256 and stored within US-based data centers. The platform runs on managed, redundant infrastructure designed to tolerate individual component failures without data loss. Restore procedures are exercised as part of provider-managed disaster recovery.

10. Personnel and access

Access to production systems and customer data is limited to authorized personnel on a need-to-know basis, requires multi-factor authentication, and is logged. Personnel with access to sensitive systems are bound by confidentiality obligations. Access is reviewed and revoked when no longer required.

11. Vulnerability management

Dependencies are monitored for known vulnerabilities and patched on a regular cadence. Security-relevant issues are prioritized and remediated ahead of routine maintenance. We welcome responsible disclosure — if you believe you have found a vulnerability, contact us at the address below before disclosing it publicly.

12. Compliance roadmap

MetrikData’s infrastructure providers (Supabase and Vercel) hold SOC 2 certifications. SOC 2 Type I certification for MetrikData is on our roadmap. This page will be updated as milestones are reached.

13. Contact

Security questions, vulnerability reports, or data processing inquiries: support@metrikdata.com.

MetrikData

Bank-statement underwriting for merchant cash advance — built for US brokers, ISOs, and funders.

Product
How it worksCase studyCalculatorPricingDocumentationFAQContact
Solutions
All solutionsMCA stacking detectionMCA underwriting softwareBank statement analysisStatement verificationMCA underwriting guideMCA glossary
Who it’s for
For ISOsFor fundersFor brokersFor lendersFor underwritersNews & pressFeature RequestAbout
Compare
All comparisonsvs Ocrolusvs MoneyThumbvs DecisionLogicvs Onyx IQvs Heron Datavs LendSaaSvs Kaaj AI

© 2026 MetrikData · 48 Wall Street, Suite 1100, New York, NY 10005

MCA Directory logoListed on MCA Directory
SecurityPrivacyTerms