Trust & data

Where your data lives.

You’re trusting an AI platform with real client information. You should know exactly where it goes, who can see it, and what you can take back. Here it is in plain English — no jargon, no hand-waving.

The short version

Your data is stored in our own database, walled off to your workspace, on your own AI account, and you can export or delete it anytime.

We don’t sell it, we don’t train models on it, and no other customer can reach it. The details below say precisely how.

Where it physically lives

Everything runs on our managed database and file storage (Supabase, hosted in the United States). It is not scattered across third-party tools, and it never sits on the machine of the person chatting with your agent.

Your workspace is walled off

Every workspace is a separate, isolated tenant. Its agents, conversations, knowledge, and logs are visible only to its own members — enforced in the database itself (row-level security), not just hidden in the interface. One client you set up can never reach another client’s anything.

What the Agent Brain actually keeps

When you fill an agent’s Brain, you type or paste text, or give a web-page link that we read and extract the text from. We store that text as a record in your database — not the original file, image, or PDF.

Today there is no “upload a document” button in the Brain. If we add one, the files would live in your own storage, and we’ll build the retention and health-data controls for it first — and tell you before it ships.

Your AI key, your account

Agents think using your own AI provider account (you bring the key), so the AI runs at wholesale on your bill — we never mark it up. Our default provider, Anthropic, does not use data sent through its API to train its models. If you connect a different provider, that provider’s policy applies — so we steer health-adjacent work to providers that don’t train on inputs.

Secrets are write-only

Your API keys and connected-tool tokens go into an encrypted vault the moment you save them. They are written in and never readable back out — not by another user, not by support, not by us. Agents use them server-side without anyone ever seeing the value.

Nothing consequential happens without a human

Sending an email, creating an event, a write, anything that binds or spends — it pauses for a person to approve. External sends are forced to that gate in code, so a misconfigured setting can never let one slip out. Agents recommend; your people decide.

Everything is on the record

Every admin, security, and configuration change writes to an audit trail that is insert-only — there is no path, for anyone, to edit or delete a record after the fact. Many changes also emit compliance evidence mapped to SOC 2 control areas.

We store an agent’s reasoning summaryand its decisions — never a raw, unfiltered stream of its private “thinking.” The record is clean, reviewable, and safe to keep.

You can leave with your data

You can export your workspace’s data or delete it at any time. It’s yours — keeping you is our job, not holding your data hostage.

What we don’t claim (yet)

Trust is easier to keep when the claims are honest, so here’s the straight talk:

  • SOC 2:we are built SOC 2-ready and generate the evidence continuously — we are not claiming a completed Type II audit.
  • Health data (HIPAA / 42 CFR Part 2): real protected health information is gated behind an explicit compliance step and a signed agreement — we don’t invite clinical records into a general workspace.
  • Stored text:Brain text is protected by database encryption-at-rest and the workspace wall, but it is not field-level encrypted — great for business FAQs and process notes, which is what the Brain is for.

Have a specific security or data-residency requirement? Talk to us— we’d rather scope it honestly than promise it on a page.