CANCEL CULTR

Cancel Cultr — Information Security Policy

Owner: Kyle Good (sole operator)
Last reviewed: September 27, 2026
Review cadence: Quarterly, and on any material change to systems or data handling.

1. Purpose & Scope

This policy defines how Cancel Cultr identifies, mitigates, and monitors information-security risks. It covers all systems that process or store user data: the mobile app, the API (Cloudflare Workers), the database (Supabase / PostgreSQL), and third-party processors (Plaid, Twilio, Anthropic).

2. Data We Handle & Classification

3. Risk Identification

Primary risks assessed:

Risks are re-evaluated at each quarterly review and whenever a new data flow or processor is added.

4. Controls & Mitigation (operationalized today)

5. Monitoring

6. Incident Response

On a suspected security incident, the operator will: (1) contain — rotate affected secrets and, if bank data is implicated, revoke Plaid items; (2) assess scope and affected users; (3) notify affected users and Plaid in accordance with the Plaid Agreement and applicable law; (4) remediate the root cause and record the incident and corrective actions.

7. Third-Party / Sub-Processors

Cancel Cultr relies on the security programs of its processors and their standard data-processing terms: Plaid (bank data), Supabase (database / authentication), Twilio (SMS), and Anthropic (notification-copy generation). No user personal information is sold or shared for marketing.

8. Vulnerability Management

Dependencies are kept current; code changes are type-checked and reviewed before deployment. Formal third-party penetration testing and SOC 2 attestation are not currently in place given the stage of the business; this policy is reviewed for uplift as the business scales.

9. Scope Statement

Cancel Cultr is operated by a single individual at an early stage. This policy documents controls that are genuinely implemented and procedures the operator commits to following; it deliberately does not claim enterprise certifications (SOC 2, ISO 27001, external audits) that are not yet in place.