Security & data

Your data stays with you.

We use hosted, trusted open models. No one else trains on your customer data — not us, not a third party. Audit-trail by default. Vault for every secret. Per-org isolation in the database.

Open models, hosted by us
We run open-weights models on infrastructure we control. Nothing is sent to a third-party LLM provider — no part of your prompt or your customer data leaves our perimeter to be trained on.
Per-org isolation
Postgres row-level security per organisation. One tenant can never read another tenant's data. Enforced at the database, not at the application layer.
Credentials in a vault
Tokens for your CRM and channels live in Supabase Vault. Only a secret_ref reaches the database. The audit log shows a SHA-256 fingerprint and the last 4 chars — never the token.
Audit-trail by default
Every user-driven change recorded in your org's activity log. Every result explainable — per-check reasoning lives in the CRM note and the ai_interactions log.
No surprise customer outreach
Results default to annotate-only. Customer-facing agents (Cold Email, Conversation Agent, Customer Outreach, etc.) require explicit org opt-in per result. You stay in control of who hears from you.
Encryption at rest + in transit
All data encrypted at rest in Supabase storage. All connections TLS-only. No plaintext credentials on disk or on the wire.
Compliance

Posture today. Plans next.

Today
  • Per-org Postgres row-level security
  • Vault for credentials (no plaintext on disk)
  • Audit trail for every user-driven change
  • Encryption at rest + TLS in transit
  • Open-model hosting (no third-party LLM provider)
  • USA + India hosting today
Under way
  • SOC 2 Type I (in progress)
  • Data-residency options per region
  • DPA library + sub-processor list
  • Standard security questionnaire turn-around < 5 business days
Need a DPA or security questionnaire?

We respond fast.

Most security questionnaires under five business days. DPA available on request.

Built for teams who need to defend the answer to 'where does our data go?'

Open models. Per-org isolation. Audit trail by default.