InstaWebhook

Trust Center

A transparent security program for webhook infrastructure.

InstaWebhook is building toward a formal compliance program. We do not claim SOC 2 certification today. This page explains currently implemented controls and how customers can evaluate the platform.

Current controls

  • Application-level encryption for payloads and secrets
  • Secure session cookies and native RBAC
  • Audit logs for sensitive actions
  • Webhook signing support
  • Rate and payload limits
  • Export and deletion controls
  • BYO database setup guide
  • Backup and restore procedures

Subprocessors

Polar.sh

Billing, checkout, subscriptions, invoices, billing portal, and billing webhooks.

Resend

Transactional email for verification, reset, invites, contact, and operational notifications.

Compliance roadmap without certification claims

InstaWebhook is building toward formal compliance readiness, but does not claim SOC 2, HIPAA, ISO 27001, GDPR, or PCI certification today.

Security contact

Send reports to security@instawebhook.com with the affected endpoint, reproduction steps, expected impact, and a safe contact method.