Legal

Security & Data Handling

Last updated: 30 April 2026

This page summarizes how Measure Copilot handles data today. It is intentionally specific about current controls and avoids claiming enterprise certifications that are not yet in place.

Data minimization

Measure Copilot asks for the minimum evidence needed to run a measurement audit: a URL, optional files, and optional notes. Users should not upload unnecessary sensitive information.

Audit files

Uploaded GTM JSON, GA4 CSV, acquisition CSV, backend orders CSV, tracking plan CSV, and extension evidence JSON are processed to generate the audit report. The product is designed so raw uploaded files are not retained after processing unless explicitly stated otherwise.

Audit reports

Generated audit reports are stored with unique IDs so users can revisit results. Reports are designed to expire after 7 days.

Authentication and billing

Authentication is handled through Supabase Auth. Payments, when enabled, are handled by Stripe. Measure Copilot does not store card numbers or bank details.

Access controls

Administrative access is limited to people who need it to operate and support the product. Production secrets are managed through hosting and provider environment variables.

Security status

Measure Copilot does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS service-provider certification, or enterprise penetration-test coverage. Those controls may be added later as the product matures.

Incident contact

Report security concerns to hi@measurecopilot.com with enough detail for us to reproduce or assess the issue.

External guidance

Our security roadmap is informed by practical guidance such as the FTC's business security resources and cloud provider best practices, but this page describes only controls actually implemented or planned for Measure Copilot.

These documents are launch templates and operational disclosures, not a substitute for legal review. Before selling broadly, have counsel adapt them to your business entity, jurisdictions, payment flow, customer contracts, and data processing obligations.