Succo security & trust

Succo stores all customer data in the EU on Supabase managed Postgres. Traffic is TLS-encrypted via Let's Encrypt. AI features run on Google Gemini through a server-side proxy; customer content is not used to train Google's models and Succo does not fine-tune on customer data. Public forms and dashboard embeds are protected by Cloudflare Turnstile, Redis-backed rate limiting, honeypots, and origin allowlists. Authentication uses Django sessions with PBKDF2-hashed passwords and mandatory email verification; Google OAuth is available, and Enterprise plans add SSO. Workspaces can be exported as JSON and permanently deleted from the in-app settings. Subprocessors: Supabase (database, EU), Google Cloud (AI), Cloudflare (Turnstile CAPTCHA), Coolify (host). Security reports go to security@succo.ai with a one-business-day acknowledgment.

Security & trust

How we handle your data.

No theatrical badges, no inflated claims. Just an honest description of where your data lives, who can touch it, and what we do to keep it safe.

For DPA, sub-processor agreements, or specific compliance questions, the Enterprise team responds within 1 business day.

EU data residency
TLS everywhere
Encrypted at rest
GDPR-ready
No AI training on your data
Data residency

Your data stays in the EU.

All workspace data — survey responses, form submissions, uploaded files, dashboards — lives in Supabase managed Postgres in the EU. No cross-border replication. Automated daily backups handled by Supabase with point-in-time recovery.

  • EU-only primary storage and backups
  • Managed Postgres on Supabase EU region
  • Daily snapshots with PITR — no manual ops required
Encryption

TLS everywhere, encrypted at rest.

Public traffic terminates at Traefik with Let's Encrypt-issued certificates. Between services inside the deployment, traffic stays on a private network. At rest, the database storage layer is encrypted by Supabase.

  • TLS 1.2+ on every public endpoint (forms, embed, app)
  • Auto-renewed Let's Encrypt certificates
  • Encrypted-at-rest storage managed by Supabase
AI & data handling

Your data isn't training material.

AI features (survey generation, bias detection, response clustering, JTBD extraction) call Google Gemini through a server-side proxy. Customer content is never used to train Google's models on the production API tier, and Succo doesn't fine-tune on your data either.

  • AI calls proxied server-side — your responses never leave the EU perimeter except as ephemeral inference inputs
  • No training of Google models on customer content (Gemini API production-tier default)
  • No fine-tuning, no shared model, no aggregated learning across workspaces
Abuse prevention

Forms and embeds, defended by default.

Every public surface — embedded forms, public surveys, dashboard embed iframes — is rate-limited, CAPTCHA-protected, and origin-allowlisted. Cloudflare Turnstile, honeypot fields, and Redis-backed rolling windows keep spam and abuse out without friction for legitimate respondents.

  • Cloudflare Turnstile on public form and survey submissions
  • Redis-backed rate limiting (5 submissions / 60 min per browser, 30s throttle)
  • Honeypot fields and origin allowlists on embed routes
  • Server-side validation on every payload
Authentication

Session-based, verified, optional SSO.

App access uses Django sessions with PBKDF2-hashed passwords. Email verification is required for every new account. Google OAuth is available as an alternative sign-in. Enterprise plans add SSO with your identity provider.

  • PBKDF2 password hashing (Django default)
  • Mandatory email verification with signed tokens
  • Google OAuth available out of the box
  • SSO (Okta, Azure AD, Google Workspace) on Enterprise
GDPR

Built EU-first, not retrofitted.

Succo was built for the European market from day one. You can export the full content of a workspace as JSON, permanently delete a workspace from the in-app settings, and never see third-party tracking pixels on a Succo form or dashboard. Respondents see no tracking either — there are no cookies set on respondent-facing pages.

  • Complete workspace export as a single JSON file
  • One-click permanent workspace delete from Settings
  • No third-party tracking on forms, surveys, or dashboard embeds
  • No cookies on respondent-facing pages
Subprocessors

A short, honest list.

We deliberately keep our subprocessor list small. Each one is named, documented, and easy to swap if your compliance team asks.

  • Supabase — managed Postgres database hosting (EU region)
  • Google Cloud (Gemini) — AI inference, production tier with no training on input
  • Cloudflare — Turnstile CAPTCHA only (no DNS/proxy traffic of customer data)
  • Coolify-managed host — application runtime (Docker Compose + Traefik)
Reporting

Found something? Tell us.

We treat security reports as a priority. Email the team directly — we acknowledge every report within one business day and keep the reporter updated through resolution. We don't threaten or pursue good-faith research.

  • Email: security@succo.ai
  • Acknowledged within 1 business day
  • Coordinated disclosure: we ask for time to fix before public posting
  • Good-faith research is always welcome
What we don't do

The shortcuts we refuse.

Honest negatives matter as much as positive claims. Here are five things we deliberately don't do.

  • No third-party analytics on respondent pages (no GA, no Hotjar, no pixel tags)
  • No selling, renting, or sharing of customer data with any third party
  • No fine-tuning AI models on your responses, ever
  • No silent data movement outside the EU (inference uses ephemeral payloads only)
  • No retention of deleted workspaces — delete means delete

Need a DPA, or have a deeper question?

Compliance reviews, custom DPA, sub-processor list updates, vulnerability reports — we'll get back within 1 business day.