Infrastructure and storage
The Heralded app at app.heralded.ai runs on Vercel in Frankfurt (fra1). The API, worker and PDF renderer run on Railway in the EU region europe-west4. The database is PostgreSQL 18 on Railway. Every hosted region is in the EU.
Backups include scheduled Railway volume backups, Railway point-in-time recovery, and a nightly encrypted database dump stored outside Railway in Cloudflare R2. We verify the dump by reading it back and keep it for 35 days. A test restore succeeded in September 2026.
Generated share cards and PDF reports are stored in Cloudflare R2 under EU jurisdiction. Customer and billing data stays in PostgreSQL. Each storage bucket has its own scoped token.
Account access
People can sign in with an email link, a six-digit email code, a passkey, Google, or a password added to an existing account. New accounts can be created only with an email link, email code or Google sign-in.
Two-factor authentication uses an authenticator app and backup codes. It is required for every sign-in method.
Organization roles are owner, admin, member, billing and viewer, with fixed permissions. Billing has no data-reading permissions.
API keys are read-only and scoped to one organization and the account that created them. We check them on every request and store only their SHA-256 hashes. Keys can expire after 30, 90 or 365 days, or never. Revoking a key deletes it. Creating one requires a recent sign-in.
MCP connections use OAuth with the read-only heralded:read scope. Each connection is bound to one organization and can be revoked.
Data protection and retention
HTTPS is used everywhere. Database connections require TLS, and off-platform database access goes through a TLS proxy. Data is encrypted at rest as our hosting providers state: see the Vercel Trust Center, Railway Trust Center and Cloudflare Trust Hub.
Connector credentials, such as Search Console and WordPress credentials, are encrypted by the application with rotating keys.
Model prompt and response text is cleared after 7 days, or after 30 days for drafting. Claim verdicts are kept for 90 days. Content deliveries and keyword metrics are kept for 30 days. Saved answers for prompts that have not been tracked for 90 days are deleted.
A cancelled subscription has a 30-day read-only period.
Account deletion runs daily. It ends memberships and grants, deletes organizations owned only by the person, removes the sign-in identity, sessions, OAuth tokens and pending invites, and anonymizes personal details. Stripe invoices and tax records are kept as the law requires. Backups expire on their own schedule; offsite database dumps are kept for 35 days.
Subprocessors
See our privacy policy for the current subprocessor list.
Contact
A data processing agreement is available on request. Email hello@heralded.ai.
To report a vulnerability, email hello@heralded.ai.