Gridstate

Security and trust

Gridstate protects customer accounts, API keys, and request records with controls for an internet-facing data API.

Effective August 31, 2026

Current controls

  • Public services require HTTPS. Gridstate does not serve customer sessions or API traffic over plaintext HTTP.
  • API keys contain 256 bits of random data. Gridstate shows each secret once and stores only its SHA-256 hash.
  • Separate database roles serve the API, workers, monitors, backups, and console. Production startup rejects broad or unexpected database privileges.
  • Tenant data uses forced row-level security. Console database access runs through narrow security-definer functions.
  • Clerk handles customer authentication. Clerk and Stripe webhooks require valid signatures before Gridstate changes account or billing state.
  • The API limits request size and duration. It also applies database-backed rate limits and records security audit events.

Service providers

These providers process limited customer data to operate Gridstate.

ProviderPurposeData
VercelPublic website and customer console hostingIP address, browser details, and web request metadata
RailwayAPI, worker, and monitor hostingAPI request data and service logs
SupabasePostgreSQL, PostGIS, and managed database backupsAccount, usage, audit, billing metadata, and published grid data
ClerkAccount authentication and session managementName, email address, account identifier, and session data
StripeSubscriptions, invoices, and payment processingCustomer, subscription, invoice, and payment details
Google WorkspaceCustomer, privacy, legal, and security emailMessage contents and contact details that you send by email

Mistral AI extracts public-source documents outside customer request handling. Gridstate does not send customer queries or API keys to Mistral.

Report a security issue

Send a clear report to tyler@grayhavenindustries.com. Do not include passwords, API keys, or unnecessary personal data.

Gridstate will acknowledge a security report within two business days. Reports that present immediate customer risk receive priority.

Availability and incidents

The public status page reports a direct production API check and published incidents.

Self-serve plans have no contractual uptime service level. A signed order form can include different service and support terms.

Assurance limits

Gridstate does not claim SOC 2, ISO 27001, PCI DSS certification, or an independent penetration test for the full service.

Stripe handles payment-card data under its own compliance program. Gridstate does not store payment-card numbers.

Email us before purchase to request a security review or data processing addendum.