Security, data boundaries and rollout requirements.
Review the controls Entekka uses today, the providers involved, and the decisions confirmed before production data is added.
Review sensitive data before upload
Do not add medical, youth-player or other special-category information until its purpose, access and safeguards have been agreed. Review the DPA framework or request a security review.
Current controls and review boundaries
The status describes the current Entekka beta. Customer-specific configuration remains part of the rollout review.
Identity and sessions
Clerk provides account identity, sign-in, sessions, invitations and organization membership.
ImplementedOrganization isolation
Protected workspace routes and CRM APIs check authentication and the active organization before private data is returned.
ImplementedServer credentials
Database, storage administration and Clerk secret credentials remain in server environment configuration.
ImplementedSensitive documents
Document categories, access, exports and storage configuration are reviewed before medical, compliance or contract workflows go live.
Confirm during rolloutHosting, transfers and retention
Production region, transfer safeguards, retention, deletion and recovery expectations are documented for the selected configuration.
Confirm during rolloutIncident responsibilities
Notification contacts, response expectations and data-protection responsibilities are agreed in the rollout and signed DPA.
Confirm during rolloutAI-assisted workflows
Production providers and review boundaries are documented before use. AI-assisted output does not replace legal, medical or professional judgment.
SOC 2 and ISO 27001
Entekka does not currently claim its own SOC 2 or ISO 27001 certification. Provider certifications do not certify Entekka.
Not claimedHow agency data reaches Entekka
Each provider has a specific role. Hosting region, transfer safeguards and production settings are confirmed for the agency configuration.
- 1 / 4
Agency team
Members and approved professional collaborators
- 2 / 4
Clerk
Identity, sessions and organization membership
- 3 / 4
Entekka on Vercel
Application hosting, delivery and aggregate measurement
- 4 / 4
Supabase
Hosted PostgreSQL database and file storage
Clerk
Identity, authentication, sessions, invitations and organization membership
Supabase
Hosted PostgreSQL database and file-storage infrastructure
Vercel
Application hosting, delivery, aggregate Web Analytics and performance measurement
Security is a shared rollout decision
The product, the agency and the agreed configuration each carry different responsibilities. Keeping those boundaries explicit prevents assumptions.
Entekka confirms
- Product access checks and server credential boundaries
- The providers used for the selected production configuration
- Support, security and incident contact routes
The agency confirms
- Who may join the organization and what access they need
- Legal basis, endpoint security, exports and internal sharing
- Which records are appropriate to place in the workspace
Confirmed together
- Sensitive-data categories, retention and document access
- Hosting, transfer, integration and recovery requirements
- The signed DPA and approval to add production data
From security questions to production approval
The review is completed before live agency information is added, not after a workflow has already started.
Share requirements
Describe the data categories, access model, integrations and questions your agency needs reviewed.
Review configuration
Confirm providers, region, retention, sensitive records, responsibilities and the proposed DPA terms.
Approve production use
Record the agreed controls and sign the required documents before live agency data is added.
Review security before adding sensitive work.
Share your data categories, access model, hosting questions and review requirements. Entekka will document the agreed configuration before production use.