Skip to main contentSkip to navigationSkip to footer
28Solutio
ServicesPricingLettersFAQAboutContact
28Solutio

Credit repair services, debt consolidation & settlement, and AI-powered legal document automation.

info@28solutio.com

Services

  • All Services
  • Credit Repair & Building
  • Debt Consolidation (28%)
  • AI Legal Documents

Company

  • About
  • Pricing
  • Compare
  • FAQ
  • Blog
  • Careers
  • Contact
  • Refer & Earn
  • Agencies

Legal

  • Privacy Policy
  • Terms of Service
  • Security
  • Self-help disclaimer

28Solutio is a self-help platform, not a law firm. Information provided is not legal advice. We do not represent you or appear on your behalf in any court. Read the full disclaimer.

© 2026 28Solutio. All rights reserved.

TwitterLinkedIn

Security

Real security claims.
No marketing badges.

Your court-bound documents include things courts subpoena: full name, address, account numbers, statutory damages claimed. We tell you exactly how those are protected — and what we use, what our providers use, and which third-party certifications you can independently verify.

AES-256-GCM
PII encryption at rest
TLS 1.3
In transit · HSTS preloaded
Postgres RLS
Row-level isolation
< 30 days
Backup deletion propagation

Encryption

How your data is protected — concretely.

Every claim below maps to specific code paths in our application. We're happy to walk through them with security researchers or compliance reviewers on request.

PII encrypted at the field level

Sensitive identifiers (full name, address, SSN-last-4, account numbers, dispute narratives) are encrypted with AES-256-GCM before they touch the database. Encryption keys are stored separately from data, rotated on a documented schedule, and never logged.

Active key version: PII_KEY_V1 · pseudonym secret separate

TLS 1.3 in transit

All client-to-server, server-to-database, and webhook traffic runs over TLS 1.3 with modern cipher suites. HSTS preload prevents protocol downgrade. We do not log decrypted PII at any layer.

Enforced via HSTS + Vercel edge

Webhook signatures HMAC-verified

Every Stripe and Denefits webhook is verified against its HMAC signature before processing. Replay-protected via timestamp tolerance. Failed verifications are logged and rejected at HTTP 400 — never silently accepted.

Stripe SDK constructEvent · Denefits SHA-256 HMAC

Row-level security on every table

Supabase RLS policies enforce that you can only read and write your own cases, letters, and documents. Policies are defined in migrations (version-controlled) and audited for every new table.

Postgres RLS · enforced at the database, not the app

Infrastructure

We don't claim certifications we don't have.

Instead, here's the audited posture of every service provider in our critical path. You can verify each one independently from the linked report.

Vercel

Hosting + edge runtime

SOC 2 Type II certified · ISO 27001 · GDPR-aware DPA. Production traffic terminates at Vercel's edge with their security posture inherited.

Verify Vercel security

Supabase

Database + auth + storage

SOC 2 Type II certified · HIPAA available on enterprise tier. Postgres backups (point-in-time recovery), JWT-based auth with refresh-token rotation.

Verify Supabase security

Stripe

Payment processing

PCI DSS Level 1 certified. We never see or store raw card numbers — Stripe Elements tokenizes card data in the browser; only Stripe customer / payment-method IDs hit our servers.

Verify Stripe security

Lob

Certified mail

SOC 2 Type II certified mail and print provider. Letter contents sent over TLS, printed and dropped into the USPS chain of custody.

Verify Lob security

Note: 28Solutio itself is not SOC 2, ISO 27001, GDPR, CCPA, or HIPAA audited. We inherit posture from our providers and operate under the rights-and-obligations frameworks below. If your organization requires direct certifications beyond inherited posture, we can scope a paid security review.

Your data rights

CCPA, GDPR, and just plain decency.

We don't gate data rights by your zip code. Whether you're a California resident, an EU citizen, or in Wyoming — these are yours by default.

Right to access

You can download a JSON export of every record we hold about you (cases, letters, documents, billing history). We honor this for any user, regardless of jurisdiction — not only CCPA / GDPR residents.

Right to deletion

You can delete your account and all associated PII at any time from Settings. Deletion is propagated to backups within 30 days. Some legal records (sent letters, court filings) are retained per statutory retention requirements — we tell you which.

Right to correction

You can correct or update any data in your profile, intake, or case records. We don't lock historical data — every record has an editable trail.

No sale of data

We do not sell, rent, or share your data with third parties for advertising, scoring, or analytics. Service providers above (Vercel, Supabase, Stripe, Lob) process data only as required to deliver the platform.

To exercise any right, email privacy@28solutio.com or use the in-app data-rights tools at /settings/privacy. We respond within 30 days; complex deletion-propagation requests may take up to 45.

Practices

Operational hygiene we actually run.

These are not aspirational. Each line below maps to a specific code path, vendor relationship, or scheduled job.

  • Multi-factor authentication available via Supabase Auth (TOTP, SMS, magic-link)
  • httpOnly + secure + SameSite=Lax session cookies
  • Server-side session timeout with refresh-token rotation
  • Password strength enforced via zxcvbn library (min score 3)
  • Rate limiting on auth + webhook endpoints (Upstash Redis)
  • Append-only event log for litigation actions (event-sourcing pattern)
  • Sentry error tracking with PII scrubbing rules
  • Quarterly dependency security review · automated via Dependabot

Responsible disclosure

Found something?

We don't run a paid bug bounty yet, but we take responsible-disclosure reports seriously and will credit researchers in our public security log on request. Please give us a reasonable disclosure window before publishing.

  • ·Email: security@28solutio.com (PGP key on request)
  • ·Include: reproduction steps, impact, and proposed remediation
  • ·Initial response: within 3 business days
  • ·Critical issues: patched within 7 days; you'll be notified before public disclosure

28Solutio is a self-help platform — not a law firm and not a substitute for one. We provide document automation, deadline tracking, and court-form templates; you remain the party of record in any case. We do not provide legal advice or represent you in court. Outcomes shown are real but not guaranteed; results depend on case facts, jurisdiction, and the litigant's own preparation. If your situation is complex, consult a consumer-rights attorney (NACA: consumeradvocates.org · NCLC: nclc.org). Read the full self-help disclaimer.