Legal
Security at Commera
Last Updated: May 8, 2026
This page summarizes how Commera LLC protects applicant data, the third-party services we rely on, and how to reach us if you discover a security vulnerability. It supplements our Privacy Policy and Terms of Service.
1. Encryption
In transit: all traffic between your browser and our site, and between our application and our service providers, is encrypted using TLS 1.2 or higher with modern cipher suites. HTTP requests are redirected to HTTPS at the platform edge (Vercel) and we set the Strict-Transport-Security header to instruct browsers to refuse plaintext connections.
At rest: applicant data is stored only inside our managed third-party services (Close, Google Drive, Upstash Redis, Vercel logs). All of these providers encrypt data at rest using AES-256 or equivalent, with provider-managed keys. Commera does not maintain a self-hosted database; we do not write applicant data to local disk.
2. Hosting & Subprocessors
Commera runs on a small set of third-party services. The following list names every provider that may process applicant personal information on our behalf:
- Vercel (hosting, edge network, function execution, log retention), SOC 2 Type 2.
- Upstash (Redis-compatible store; IP-derived rate-limit keys with short retention, plus tokenized application records containing applicant-submitted form data), SOC 2 Type 2.
- Close (lead/applicant CRM record system; full applicant PII stored here), SOC 2 Type 2.
- Google Drive (applicant document storage, bank statements, identification, and voided check images), SOC 2 Type 2, ISO/IEC 27001.
- Resend (transactional email delivery; applicant email + name + summary in outgoing notifications), SOC 2 Type 2.
- Google (Google Analytics 4 via the Google tag; site usage data and cookie identifiers, no application form contents), ISO/IEC 27001.
- PostHog (product analytics and error monitoring; site usage data and application funnel metadata such as requested amount and revenue figures; no names, contact details, or documents), SOC 2 Type 2.
- Trustpilot (review widget display; loads on every page), does not receive applicant form data.
- Termly (cookie consent UI; loads on every page), does not receive applicant form data.
Analytics services (Google Analytics 4, PostHog) receive site usage data and application funnel metadata (for example, requested amount and revenue figures); they do not receive names, contact details, or uploaded documents. We do not run third-party advertising or retargeting. If our use of these services changes, we will update this page and our Privacy Policy first.
3. Access Controls
Access to systems that process applicant data is limited to personnel with a documented business need. Production access requires multi-factor authentication. Credentials are never committed to source control and are rotated when personnel leave.
4. Application Security
- Form submissions are rate-limited per IP address on every submission endpoint.
- The application enforces input validation and length limits on every field, server-side.
- TCPA consent is captured with a server-validated timestamp to defend against replay/automation.
- For Vermont applicants, an additional state-required opt-in (8 V.S.A. § 10204) is captured before any data is shared with Funding Partners.
- Analytics scripts are limited to the services named in Section 2 and do not receive names, contact details, or uploaded documents.
5. Data Retention
Applicant records are retained as described in Privacy Policy § 10, generally seven years from the most recent application or transaction, consistent with financial-services recordkeeping requirements. Rate-limit counters auto-expire one hour after they are written.
6. Breach Notification
If we confirm an unauthorized access event affecting applicant personal information, we will notify affected applicants and the applicable state regulators within the timeframe required by law, and in any event no later than 72 hours after confirmation, where practicable. We will provide the categories of information affected, what we have done to contain the incident, and steps applicants can take to protect themselves.
7. Compliance Posture
- GLBA, Privacy Policy § 4.6 implements the federal Gramm-Leach-Bliley privacy notice and opt-out for nonaffiliate marketing sharing.
- FCRA, Terms of Service § 4.2 implements the soft-pull permissible-purpose disclosure under 15 U.S.C. § 1681b.
- State commercial financing disclosure laws, see State Availability page.
- State privacy laws, Privacy Policy § 7 enumerates rights under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, and Vermont 8 V.S.A. § 10204.
- SOC 2 Type 2, Commera does not currently hold a SOC 2 attestation. We are evaluating the scope and timeline for a Type 2 examination.
8. Vulnerability Disclosure
If you have discovered a security vulnerability affecting Commera, please email contact@commerafunding.com with "Security Disclosure" in the subject line. We aim to acknowledge reports within two business days. We do not currently run a paid bug bounty program.
In scope: commerafunding.com and any subdomain owned by Commera LLC.
Out of scope: vulnerabilities in third-party services listed in Section 2 (please report those directly to the vendor); social-engineering of Commera personnel; volumetric attacks against the platform.
Researchers who follow this process and act in good faith will not be subject to legal action by Commera. We will publicly credit responsible disclosure on this page with the reporter's consent.
9. Contact
Commera LLC
Attention: Security
5830 E 2nd St, Casper, WY 82609
Email: contact@commerafunding.com
Phone: +1 (307) 667-1250
This page describes Commera's security practices as of the Last Updated date above. It is informational and does not create any contractual obligation beyond what is stated in our Terms of Service.
