Loading...
Loading...
Security and compliance, in the open.
FreshCut NYC moves food, payments, and personal data for customers, independent shops, and delivery workers across the five boroughs — so we treat security and compliance as product features, not paperwork. This page summarizes our posture in plain language: which frameworks we align with (and exactly how far that alignment goes), the concrete safeguards implemented in the platform, the infrastructure it runs on, and the live pages where you can verify our claims yourself. It complements our Security Policy and Privacy Policy.
A SOC 2-aligned control matrix maps every AICPA TSP 100 trust-service criterion (CC1–CC9, Availability, Confidentiality, Processing Integrity, Privacy) to the platform feature that implements it, with live evidence flowing from our append-only audit log. A Type 2 report requires an independent CPA examination, which has not yet been engaged — the controls and evidence pipeline are built so that engagement is a walkthrough, not a rebuild.
Our information-security controls are aligned with ISO/IEC 27001:2022 Annex A — access control, cryptography, operations security, supplier relationships, and incident management all have implemented counterparts in the platform. We have not undergone certification by an accredited body and do not claim one.
FreshCut is not a covered entity or business associate under HIPAA and holds no protected health information (PHI). We nonetheless voluntarily apply HIPAA Security Rule-grade administrative, technical, and physical safeguards to customer data — encryption in transit, role-based access, audit trails, and breach-response procedures.
Cardholder data is fully delegated to Stripe, a PCI DSS Level 1 service provider — the highest level of certification available. Card numbers are entered into Stripe-hosted elements and never touch or get stored on FreshCut servers; we handle only opaque payment tokens.
We comply with NYC Department of Consumer and Worker Protection rules as a binding legal obligation: per-order fee caps (§20-847.2) are enforced by canonical constants and a CI-time isolation test, delivery workers are paid at or above the $22.13/hr minimum with automatic top-ups, and itemized pay statements and annual reports are generated from the same audited data.
We maintain the reasonable administrative, technical, and physical safeguards the New York SHIELD Act requires, and operate a breach-notification process: affected users and the New York Attorney General are notified within the statutory timeframes if personal information of New York residents is ever compromised.
Beyond the static matrices, a catalog of automated checks continuously probes the running platform — security-header configuration, password hashing, webhook signature verification, audit-log freshness, backup and disaster-recovery artefacts, and more — each mapped to SOC 2, ISO/IEC 27001, and HIPAA Security Rule control ids. The aggregate result is published here; this is continuous monitoring in the open, not a certification.
Automated checks passing
4 of 25
Last automated run: 2026-09-09 08:00 UTC
Checks re-run continuously; the nightly compliance job records every run in our append-only audit log.
Example checks currently passing
We publish aggregate counts and passing examples only — individual failure details stay internal so this page never doubles as a reconnaissance aid.
The platform runs on Vercel's managed edge network, with data stored in managed PostgreSQL accessed exclusively through a typed ORM (no hand-built SQL in request paths). Payments, partner payouts, and identity verification are handled end-to-end by Stripe. The complete list of subprocessors — who they are, what data each receives, and why — is published in our Privacy Policy, §3.1, and each is bound by a data-processing agreement.
Don't take our word for it — these pages are live:
Honesty is the point of this page, so to be explicit: “aligned” and “audit-ready” are not the same as “certified” or “attested”. FreshCut has not yet engaged an independent CPA firm for a SOC 2 Type 2 examination, nor an accredited body for ISO/IEC 27001 — those engagements are the natural next step for an operator or enterprise buyer who requires a formal report, and the control matrix, evidence pipeline, and audit log documented above exist precisely to make that step fast. Where we do state compliance outright — NYC DCWP rules, the NY SHIELD Act, and PCI DSS handling via Stripe — it is because those obligations are binding today and actively enforced in the platform.
Questions from procurement or security teams: security@freshcut.nyc.