Security
Security and data handling
Each client's data lives in its own database schema and storage bucket, every action that touches a client is written to an append-only audit log, all traffic is encrypted in transit, and AI providers are reached only through their business APIs, which do not train models on your data. This page states what is in place today and what is not yet.
Every statement on this page was checked against the platform itself, and each is dated in our records. Where something is not in place yet, we say so instead of leaving it out.
Access control
Sign-in is invite-only (no public sign-up) through our identity provider, by a one-time email link or code. Every account has a role, access to a client engagement is granted per person and can be revoked at once, and team members use their own accounts.
Data segregation
Each client engagement has its own database schema and its own object-storage bucket. Code is shared; data never is. Access is granted per engagement and a client account can see only its own engagement.
Audit logging
Every action that touches a client (messages, files, signatures, invoices, access changes) is written to an audit log in the same transaction as the action. The log is append-only at the database level: neither the application nor the database owner can edit or delete entries.
Encryption in transit
All traffic from the internet reaches our platform over HTTPS (TLS).
Hosting and subprocessors
Hosting is in the United States, in DigitalOcean's New York data center (NYC3). Public website pages are cached by Cloudflare's network; client data is not.
Subprocessors: Cloudflare (DNS and traffic protection), DigitalOcean (hosting), Resend (email delivery), Stripe (payments), Hexclave (sign-in), OpenAI and Anthropic (AI processing).
AI providers
Meeting audio is transcribed by OpenAI and specifications and drafts are written by Anthropic, both through their business APIs, which do not train models on API data. Both providers may retain API data for up to 30 days for abuse monitoring; zero-data-retention terms are not yet in place with either.
Personal data
Account data for the people we invite (name, email). Usage telemetry from deployed tools carries a role and a one-way hash of the user id, never names, notes or free text.
Integrations
Every inbound webhook (email, payments, messaging) is verified by its provider's signature and replays are rejected; an unverifiable request is refused. Integration secrets are held in a key broker, never in code.
Vulnerability management
We scan our application dependencies and every container image we run automatically each week. Any new critical or high finding with a fix available alerts the team, and we rebuild with the fix. Images are rebuilt with current operating system security updates, run without unneeded tools, and our database runs as a non-root user.
Incident response
We follow a written incident response plan: contain within the first hour, assess within 24 hours, and notify every affected client in writing within 24 hours of confirming an incident, then a written review within 10 business days.
Business continuity
If the platform is unavailable, each client's crew switches to the documented paper or spreadsheet fallback in their handover pack; the client and we can each disable the automation; restore times are stated per client.
Retention and deletion
We keep a client's data for the engagement and delete it on the schedule in the contract, by default 90 days after the engagement ends. Before deletion the client receives a complete export of their records and files. Deletion removes their database schema, stored files, sign-in accounts and conversations, and we issue a certificate of deletion listing what was deleted and what we keep for accounting (invoices and payments) and security (the audit log, which records actions, not content).
E-signature
Our own e-sign records the signer's typed name, drawn signature, consent, IP address, device and time, and the SHA-256 fingerprint of the document before and after signing. The signed file carries a certificate page and can be checked against the record on a public verification page.
Certifications
We do not hold a SOC 2 report or ISO 27001 certification and do not claim either. Our security posture document follows the structure of the NIST AI Risk Management Framework without claiming certification.
Not in place yet
- Off-host encrypted backups. In progress; we will describe the backup arrangement here once it is in place.
- Encryption at rest. Not yet confirmed for our hosting volumes; ask us and we will answer for your engagement.
- Penetration test. Scheduled once every part of the platform is built.
Questions people ask
Is our data used to train AI models?
No. Meeting audio is transcribed by OpenAI and specifications and drafts are written by Anthropic, both through their business APIs, which do not train models on API data. Both providers may retain API data for up to 30 days for abuse monitoring; zero-data-retention terms are not yet in place with either.
Do you have SOC 2 or ISO 27001?
No. We do not hold a SOC 2 report or ISO 27001 certification and do not claim either. Our security posture document follows the structure of the NIST AI Risk Management Framework without claiming certification.
Where is our data hosted?
In the United States: DigitalOcean's New York data center (NYC3). Public website pages are cached by Cloudflare's network; client data is not.
What happens to our data when the engagement ends?
It is deleted on the schedule in the contract, by default 90 days after the engagement ends, after you receive a complete export. You get a certificate of deletion listing what was deleted and what we keep for accounting and security.