Trust and security
Last updated 6 October 2026
Golden Dorado LLC designs, builds and operates custom systems that run our clients' day-to-day work, often including quoting and billing. This page sets out how we host and protect those systems, written for the finance, IT, security and procurement teams who review a new vendor. Everything here describes how we operate today.
Live system statusThe short version
- Each client system runs in its own isolated environment, in the United States (AWS, Ohio region).
- Data is encrypted in transit and at rest, every change is recorded in an audit trail, and access is by role.
- Databases are backed up every night to separate, encrypted storage, and we rehearse restores.
- Systems are checked every 5 minutes, with live results on our status page.
- We notify clients within 72 hours of confirming an incident that affects their data.
- Your data is yours. You can export it at any time, and it is deleted when our agreement ends.
1.Hosting and data location
Client systems run on Amazon Web Services in the us-east-2 region (Ohio, United States). Each client gets its own environment: a separate database, separate file storage and separate configuration. No database, storage or credentials are shared between clients.
| Layer | Service | Location |
|---|---|---|
| Application | AWS Lambda behind Amazon API Gateway | AWS us-east-2, Ohio |
| Database | PostgreSQL, managed by Supabase | AWS us-east-2, Ohio |
| Files and backups | Amazon S3, encrypted and versioned | AWS us-east-2, Ohio |
| System email | Amazon SES, signed with DKIM | United States |
Client data stays in the United States. We do not sell client data, use it for advertising, or use it to train AI models.
2.Security controls
- Encryption in transit: TLS 1.2 or higher on every connection, with HTTPS enforced.
- Encryption at rest: AES-256 for the database, file storage and backups.
- Sign-in: production systems can use your own Microsoft 365 or Google accounts for single sign-on, so your IT team controls who gets in and can remove access centrally. Without single sign-on, users sign in with one-time codes sent by email.
- Permissions by role: people see and do only what their role allows, and finance steps can require two different people (for example, the person who requests an invoice cannot also verify it).
- Audit trail: every change to a record, amount or status is kept in an append-only log of who changed what, and when.
- Secrets: credentials live in managed secret storage or encrypted configuration, never in source code.
3.Backups and recovery
Every client database is backed up automatically each night to separate, encrypted, versioned storage, and each backup is kept for 35 days. Each backup records the number of rows in every table, and our restore rehearsal loads a backup into an empty database and checks it row for row against that record. A failed backup alerts our team immediately.
All infrastructure is defined as code and kept in version control, so an environment can be rebuilt from scratch and then restored from its latest backup.
4.Monitoring and availability
Each hosted system is checked every 5 minutes. Two failed checks in a row alert our team, and error alarms watch the applications themselves. Current status and 90 days of history are public at status.golden-dorado.com. Availability and support response commitments are set out in each client's support agreement.
5.How changes are made
Every change is made in version control, released through a scripted, repeatable deployment, and followed by an automated end-to-end test of the live system. Changes a client requests are tracked from request to release, and releases are documented.
6.Our people and access
We are a small, senior team. Our lead engineer holds the AWS Certified Solutions Architect, Associate certification. Our staff access a client system only to operate, support or fix it, and access to our cloud accounts is recorded by AWS CloudTrail.
7.Certifications and assurance
Our systems run on providers that are independently audited:
- Amazon Web Services: SOC 1, SOC 2 and SOC 3 reports, ISO 27001, 27017 and 27018, PCI DSS and more. AWS compliance programs
- Supabase: SOC 2 Type II. Supabase security
Golden Dorado itself does not hold a SOC 2 report or an ISO certification today, and we will not suggest otherwise. In their place we complete your security questionnaire (your own, or a standard one such as CAIQ or SIG Lite), share the documents listed below, and walk your team through how a system is built and run.
8.Subprocessors
These companies process data on our behalf for the client systems we run. We give clients 30 days' notice before adding one.
| Company | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, file storage, backups, email delivery, monitoring | United States (Ohio) |
| Supabase, Inc. | Managed PostgreSQL database | United States (AWS Ohio) |
| Stripe, Inc. | Billing our own invoices: the client company's billing contact and payment details only, never client system data | United States |
| Microsoft or Google | Single sign-on, only when the client turns it on, under the client's own Microsoft 365 or Google account | The client's own tenant |
9.Incident response
We follow a written incident response plan. If we confirm a security incident affecting a client's data, we notify that client without undue delay and within 72 hours, keep them updated while we contain and fix it, and then provide a written report of the cause and the changes we made.
10.Reporting a vulnerability
If you believe you have found a security problem in golden-dorado.com or a system we run, email security@golden-dorado.com with enough detail for us to reproduce it. We acknowledge reports within 2 business days and keep you informed until it is resolved.
We will not pursue or support legal action against good-faith research that avoids privacy violations, data destruction and service disruption, stays within your own test accounts, and gives us reasonable time to fix the issue before disclosure. Do not access, change or keep other people's data, and do not run denial-of-service, spam or social-engineering tests. We do not offer payment for reports. Our contact details are also published in security.txt.
11.Documents for your review
Available on request to support@golden-dorado.com:
- Security overview
- Completed security questionnaire (CAIQ-style), or yours filled in
- Master services agreement, statement of work and support agreement templates
- Data processing agreement and mutual NDA
- Information security, incident response, backup and continuity, data retention and access control policies
- Form W-9 and certificate of insurance
12.Company information
Golden Dorado LLCAn Arizona limited liability company
7252 N Central Ave, Phoenix, AZ 85020
General and vendor documents: support@golden-dorado.com
Security: security@golden-dorado.com
You can confirm our registration on the Arizona Corporation Commission's entity search.
Related: Terms of service, Acceptable use policy, Privacy policy.