Security
Last updated 28 Sep 2026
Your obligations, deadlines and team records are sensitive. This page explains how Regmindr keeps them private.
Each company's data is isolated
Every record in Regmindr belongs to one organization. Access rules are enforced inside the database itself, not only in the app, so a user can only ever read or change the data of organizations they are a member of. Even a mistake in the application code cannot expose one company's data to another.
Only the people you invite
Nobody can join your workspace without an invitation from your team. Each member has a role:
- Members see the workspace and mark obligations as done.
- Admins also manage obligations and invite or remove members.
- Owners also decide who becomes an admin.
A record of every change
Changes to obligations are written to an audit log that everyone in the organization can review. Users can add entries through their actions but cannot edit or delete them.
Stored in the EU
Your data is stored in a database in Ireland, and the app's servers run in Dublin, so your workspace data is stored and processed in the EU.
Encrypted in transit and at rest
All traffic to Regmindr uses HTTPS. The database is encrypted at rest with AES-256. Passwords are stored only as a secure hash and are never visible to anyone, including us.
Trusted infrastructure
Regmindr is built on Supabase (database and sign-in) and Vercel (hosting). Both providers are independently audited to the SOC 2 Type II standard. Which data each provider handles is listed in the privacy policy.
Reporting a security issue
If you think you have found a security issue, write to contact@regmindr.com. We read every report, reply as soon as possible, and ask that you give us time to fix it before sharing it publicly.