Security

Last updated September 1, 2026

Security and recordkeeping aren't a feature we bolted on — they're the reason Solander exists. What follows describes how the product is built, not a checklist assembled for this page.

Data protection

Data in transit is encrypted (TLS). Documents are stored in Cloudflare R2. The application database and authentication run on Supabase. The application is hosted on Vercel.

The record

Every financial change and every AI suggestion an advisor approves is captured as a write-once, never deleted entry at the moment of action. AI-generated output doesn't touch a client's record until an advisor reviews and approves it — and that approval is itself part of the record. Firms can export their records at any time.

AI handling

AI features process firm-submitted content to do their job — reading an email to suggest a classification, for example. That content is not used to train our AI provider's models, per our agreement with them. AI output is always a suggestion an advisor reviews before it's accepted into the record.

Incident commitment

If we confirm a security incident affecting a firm's data, we notify that firm within 72 hours of confirming it.

Vendor diligence

Evaluating Solander for your firm? We'll walk through our architecture and data handling as part of your vendor diligence — ashaw@solandersoftware.com.

What we don't do

We don't sell firm or client data. We don't use it for advertising — ours or anyone else's. We don't train third-party AI models on firm-submitted data.

Questions about these documents: ashaw@solandersoftware.com