🛡Data Protection
Your content belongs to you. Uploaded documents and data are processed solely to deliver the functionality you request, never used to train public AI models, and kept logically isolated between tenants.
- Customer data is logically isolated per workspace
- Your content is never used to train shared or public models
- Configurable data-retention windows with hard-delete on request
- Regular encrypted backups with tested restore procedures
🔒Privacy & Security Practices
Privacy is designed in, not bolted on. We collect the minimum data needed to run the service, are transparent about how it is used, and never sell personal data.
- Privacy-by-design and data-minimization principles
- Clear data-processing agreements (DPA) available for customers
- Vendor risk reviews before any subprocessor is onboarded
- Documented incident-response and breach-notification process
🏗Infrastructure Security
We run on hardened, reputable cloud infrastructure with defense-in-depth. Networks are segmented, systems are continuously patched, and everything is monitored around the clock.
- Hosted on SOC 2-aligned cloud providers with regional options (US, EU, APAC)
- Network segmentation, firewalls, and private networking
- Continuous monitoring, logging, and anomaly alerting
- Routine vulnerability scanning and third-party penetration testing
🔑Access Control
Access to data is granted on a strict need-to-know basis. Both your team and ours operate under least-privilege, role-based controls with strong authentication.
- Role-based access control (RBAC) for every account
- Single Sign-On (SSO) and SAML support on enterprise plans
- Multi-factor authentication (MFA) for privileged access
- Audit logs for sensitive actions and administrative changes
🔐Encryption Standards
Data is protected with strong, industry-standard cryptography at every stage — moving across the network and sitting at rest in storage.
- TLS 1.2+ for all data in transit
- AES-256 encryption for data at rest
- Managed key rotation and secure secrets storage
- Encrypted database backups
✅Compliance & Best Practices
We align our program with recognized frameworks and continually improve through audits, training, and disciplined engineering practices.
- SOC 2 Type II program and GDPR-aligned data handling
- CCPA support and DPAs for regulated customers
- Secure software development lifecycle (SSDLC) with code review
- Ongoing security awareness training for all staff