Every vendor that touches customer data.
Sub-processor changes notified 30 days in advance via email and the public changelog.
How long we keep what.
AES-256 per organisation. Vault-rotated.
At rest
Conversation content encrypted via pgp_sym_encrypt (AES-256) with per-organisation key derivation. Database backups encrypted.
In transit
TLS 1.3 preferred (1.2+ minimum), HMAC-SHA256 webhook signatures, Cloudflare Full (Strict) SSL.
Secrets
HashiCorp Vault 3-replica Raft HA. Emergency rotation in ~35 seconds (was 10-15 min via CI/CD). 90-day audit log.
Hosting
DigitalOcean SGP1. Multi-cluster Kubernetes. Internal VPC 10.104.0.0/16, zero public egress.
Detect, triage, contain, eradicate, recover, post-mortem.
Post-mortem required for every P0/P1. Includes timeline, root cause, corrective actions, and what we changed to prevent recurrence.
SOC 2 Type II, where we are on the path.
We have implemented technical controls aligned with SOC 2 Type II (AES-256 encryption, RBAC, Vault, 5-layer defence-in-depth). Formal independent attestation is on our roadmap; we'll publish the auditor and target date here once engaged.
Infrastructure providers we sit on are certified, DigitalOcean (SOC 2 Type II + ISO 27001), Cloudflare (SOC 2 + PCI-DSS + ISO 27001), HashiCorp Vault (SOC 2 Enterprise).
Data Processing Addendum on request.
We don't yet publish a public DPA template. To request one for your procurement review, email [email protected]. Turnaround is 5 business days. Vendor DPAs (Anthropic, OpenAI, Google) available on the same request.
Procurement asking for more?
Send the security questionnaire (we'll handle CAIQ, SIG, or your custom format). We typically turn it around in 5 business days.
