How we handle the data you put in.
Where it lives, who can reach it, what gets written down, and what we have not finished yet. No badges we have not earned.
Sign in your way
Single sign-on through your existing provider, passkeys, or password with two-factor. Configured per organisation, rotated without a redeploy.
Permissions that mean something
Roles you define, scoped to your own records, your team, or everything. The AI inherits the permissions of whoever asked and can be given fewer, never more.
Everything is on the record
An append-only history of every change — who, when, and what it replaced. People and AI are recorded identically.
Encrypted where it matters
Credentials for the services you connect — email, payments, storage, AI providers — are encrypted at rest, not stored in the clear.
Your data leaves when you do
Export everything at any time, records plus full change history. After cancellation we hold it for 30 days, then delete it permanently.
Built for privacy law
Data-deletion requests with a 30-day cancellation window, per-region data residency, DPA and sub-processor list on request.
What we have, and what we do not.
HIPAA mode and a BAA are available today. SOC 2 Type II is in progress and we will say so until it is not — you will see the report and its observation period when there is one, not before. ISO 27001 is being evaluated. We would rather lose a deal than win one on a badge we have not earned.
Q.01Where is our data stored?
In the region you choose, and it stays there. Tell us your requirement and we will confirm exactly which services touch your data and where.Q.02Can we get a security-review packet?
Yes — architecture diagram, sub-processor list, DPA and HIPAA BAA under NDA, within one business day of asking.Q.03What happens if there is an incident?
You hear from us directly, with what happened, what was affected and what we did — not a status page you have to go looking for.Q.04Can the AI see things our staff cannot?
No. It operates with the permissions of the person who asked, and can be restricted further. It cannot open a record that person could not open themselves.
