Security

Your data is yours. Period.

Enterprise-grade security for your most sensitive commission data. We built Stateable with the same standards used by the largest financial institutions.

SOC 2 Type II

Stateable undergoes annual SOC 2 Type II audits conducted by independent third-party firms. These audits verify that our security controls are not only designed correctly, but operating effectively over time.

Encrypted Everywhere

Every byte of your data is encrypted with AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed through a dedicated key management service with automatic rotation.

No Data Sharing. Ever.

Your commission data is never sold, shared with third parties, or used to train AI models. Each customer's data is logically isolated. When you delete your data, it's permanently removed.

How We Handle Your Data

Upload

Encrypted in transit via TLS 1.3, encrypted at rest with AES-256.

Process

Isolated environments. Each customer's data is logically separated.

Store

SOC 2 certified US data centers with redundant backups.

Delete

Request deletion anytime. Data permanently removed within 30 days.

Compliance & Certifications

SOC 2 Type II

Audited annually by independent third parties.

HIPAA Ready

Compliant data handling for health insurance commissions.

Data Residency

US-based data centers, no international data transfers.

Penetration Testing

Annual third-party penetration testing.

Common Security Questions

Ready to stop chasing commissions?

See how Stateable turns every statement into clean, actionable data.