Skip to main content
Patriot BioSolutions

Trust Center

Security and Trust Center

Operational controls, infrastructure protections, and disclosure routes for procurement teams reviewing Patriot BioSolutions.
Last updated: September 30, 2026

ACCESS

Protected operational routes

Buyer, order, and admin workflows require authenticated sessions and role checks before protected data is rendered.

DATA

Transaction evidence handling

Compliance evidence, order context, and procurement inputs are guarded by server-side validation and authorization checks.

DISCLOSURE

Public security contact

Security issues can be reported directly to security@patriotbiosolutions.com with endpoint, timing, and reproduction context.

Infrastructure and Data Protection

Patriot BioSolutions uses the managed services below. Contact us for evidence relevant to your security review and contract requirements.

Hosting

Vercel application hosting and content delivery over HTTPS

Database

Supabase PostgreSQL with application authorization and database access policies

Authentication

Supabase Auth with server-side session and role checks

File Storage

Supabase Storage with signed URLs and access-controlled upload endpoints

Monitoring

Sentry error monitoring and PostHog usage analytics; see the Privacy Notice for information collected and opt-out controls

Email

Resend for transactional notifications and order confirmations

Application Security Controls

  • Server-side session and role checks for protected application procedures.
  • Schema validation for defined API inputs.
  • Request-origin validation on protected browser mutation paths.
  • Rate limiting on protected API procedures.
  • Content Security Policy headers, including nonce-based authorization on authenticated routes.
  • Authorization, validation, and logging controls reviewed as part of application maintenance.

Report a Security Concern

Email security@patriotbiosolutions.com with endpoint, timing, and reproduction context.

Incident Response Process

  1. Review the report and acknowledge receipt
  2. Assess severity and scope of reported vulnerability
  3. Contain and remediate the issue
  4. Notify affected parties if data exposure occurred
  5. Document resolution and update security controls

Service Assurance

Operational commitments for procurement teams

These are the baseline service and governance signals used during buyer onboarding and vendor risk review.

Security + Governance

Response approach

Timing varies by request complexity

Intake requests are reviewed in order of urgency and available operational capacity.

Support availability

Handled during standard U.S. business hours

Sourcing, onboarding, and documentation support are handled during active staffing windows.

Policy maintenance

Reviewed on a recurring basis

Threshold and citation references are maintained and updated when source changes are identified.