Security

Security, stated plainly.

What we do today, and what we don’t have yet.

Where we are today

We’re not SOC 2 or ISO 27001 certified. We’ll answer your security questionnaire in writing.

Send us your questionnaire

Your logins

  • We use your own logins, ideally a separate account with the least access.
  • You share them through a one‑time link, never by email.
  • They’re kept in a secret manager. Only the automation reads them.

Your own environment

  • Each client gets a dedicated environment, with no shared databases or secrets.
  • We host it, or deploy it into your own cloud account.

Your data

  • Encrypted in transit and at rest.
  • We don’t train AI models on your data, and neither may our AI providers.
  • Source files are deleted after 30 days by default. Your DPA sets the rest.
  • When you leave, we return or delete your data, and confirm it in writing.

A record of every run

  • Every step is logged. Open any item to see what was read, decided, and written.

Other people’s systems

  • We only automate where the terms allow it, and never get around security checks.
  • If a site blocks automation, we stop and find an approved route.

If something goes wrong

  • We follow a written incident process.
  • If an incident affects your data, we tell you within 48 hours of finding out.

Paperwork we’ll sign

  • A mutual NDA
  • A data processing agreement
  • Your security questionnaire, answered in writing

What we don’t have yet

  1. An independent penetration test.
  2. Healthcare work under HIPAA. We don’t take on health records today.

Next step

Talk to the engineer who’d handle your data.

Bring your IT or security lead.