Trust center
Where compliance actually stands, with the dates we are working to.
No certification on this page is held today. SOC 2, ISO 27001 and HIPAA appear here as a dated roadmap, marked Planned, because implying a report we do not have is the one thing a trust page must never do.
Status as of
Certifications held0
On the roadmap4
01 — Compliance / 7 frameworks
Every framework, what it actually is, and whether we hold it.
Two of the rows below are laws, not certifications — there is no certificate to hold for CCPA or HIPAA, and anyone who shows you one is selling something.
| Framework | What it actually is | Status | Who can see evidence |
|---|---|---|---|
| SOC 2 Type I | Point-in-time report on control design | Planned. Not achieved. A target date, not a commitment that it is done.Target | Growth and above under NDA, once issued |
| SOC 2 Type II | Report on operating effectiveness over an observation window | Planned. Not achieved. A target date, not a commitment that it is done.Target | Growth and above under NDA, once issued. Observation window 2027-06-01 to 2027-11-30 |
| ISO/IEC 27001 | Certified ISMS | Planned. Not achieved. A target date, not a commitment that it is done.Target | Certificate public; Statement of Applicability under NDA on Scale and above |
| CCPA / CPRA | Law, not a certification. We do not sell or share personal information as those terms are defined | Operational (not a certification). A legal programme that runs today. Not a certification. | Privacy policy |
| HIPAA | There is no such thing as HIPAA certified. It is a BAA plus safeguards for ePHI | Not offered. Not available today at any plan level.Target | Enterprise only, once live. Acceptable use forbids ePHI until then |
| Penetration test | Independent annual web and API test | Planned. Not achieved. A target date, not a commitment that it is done.Target | Letter of attestation public; full report under NDA on Scale and above |
| Vulnerability disclosure | Coordinated disclosure programme | Operational. A programme that runs today. Not a certification. | This page and security.txt |
Allowed status values on this page are Held, Operational, Planned and Not offered. Certified is not one of them for CCPA or HIPAA, because it does not exist for either.
02 — Roadmap / 5 dated items
The roadmap, and why each date is where it is.
Controls have to run before an auditor can say they ran. These dates come from that constraint, not from what would look good on a slide.
Milestone 01
SOC 2 Type I
Point-in-time report on control design
Growth and above under NDA, once issued
Planned. Not achieved. A target date, not a commitment that it is done.TargetMilestone 02
SOC 2 Type II
Report on operating effectiveness over an observation window
Growth and above under NDA, once issued. Observation window 2027-06-01 to 2027-11-30
Planned. Not achieved. A target date, not a commitment that it is done.TargetMilestone 03
ISO/IEC 27001
Certified ISMS
Certificate public; Statement of Applicability under NDA on Scale and above
Planned. Not achieved. A target date, not a commitment that it is done.TargetMilestone 04
HIPAA
There is no such thing as HIPAA certified. It is a BAA plus safeguards for ePHI
Enterprise only, once live. Acceptable use forbids ePHI until then
Not offered. Not available today at any plan level.TargetMilestone 05
Penetration test
Independent annual web and API test
Letter of attestation public; full report under NDA on Scale and above
Planned. Not achieved. A target date, not a commitment that it is done.Target
How the SOC 2 dates were derived
A Type I report describes control design, so the controls have to be implemented and frozen first. From a design start in September 2026: implement through Q4 2026, freeze in Q1 2027, fieldwork in April 2027, report by 2027-05-31.
A Type II report covers operating effectiveness over an observation window. Six months is the shortest window a serious auditor will sign, which puts the first Type II at 2027-12-15 — not next quarter. ISO 27001 is a full ISMS cycle with its own scope, statement of applicability, internal audit and two-stage certification; the target is a year after the first Type II, not a parallel rush.
What the plans entitle you to
Growth and above may receive the SOC 2 report under NDA when it is issued. Status today: Planned, report target 2027-12-15.
Enterprise may sign a business associate agreement when one is offered, target 2027-06-30. Until that date we do not sign a BAA and protected health information is forbidden in run payloads on every plan.
What is operational today
These are running programmes rather than certificates. The evidence is a document you can read, not a seal.
| Programme | What it actually is | Evidence |
|---|---|---|
| CCPA / CPRA | Law, not a certification. We do not sell or share personal information as those terms are defined | Privacy policy |
| Vulnerability disclosure | Coordinated disclosure programme | This page and security.txt |
03 — Subprocessors / 6 platform, 3 conditional
Every entity that may touch customer personal data, named.
Model providers are on this list even though buyers below Scale never choose one. If a vendor is not here, we are not allowed to use them on your data.
| Legal entity | Purpose | Data classes | Processing location | Contract | In production at launch |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Server hosting, database, and backups | Account data, workspace config, connector secrets, run payload, run metadata, audit events, support data, website inquiries | Germany (Nuremberg) | Data processing agreement — to conclude before launch | Yes |
| Zoho Corporation B.V. | Email hosting for our mailboxes | Email you send us and our replies, including support requests | EU (Zoho EU data centers) | Data processing addendum — to request before launch | Yes |
| Stripe, Inc. | Payments, invoices, and tax on our own fees | Billing identity, card last four, subscription state. No card number on our side | US | Stripe DPA | No — checkout records a waitlist and takes no payment |
| OpenAI, LLC | Model inference | Prompt, retrieved context and completion, for products that call a model | US | DPA plus zero-retention or no-training terms where offered | No — no product in this build calls a model |
| Anthropic, PBC | Model inference | Prompt, retrieved context and completion, when routed there | US | DPA plus no-training or zero-retention terms where offered | No — no product in this build calls a model |
| Google LLC (Google Cloud / Vertex AI) | Model inference | Prompt, retrieved context and completion, when routed there | US | Google Cloud DPA | No — no product in this build calls a model |
Conditional subprocessors — only if you switch the feature on
| Legal entity | What turns it on | Data | Processing location |
|---|---|---|---|
| Slack Technologies, LLC | A Slack webhook is configured for new-inquiry alerts | Inquiry details: email, name, company, and the message | US |
| Google LLC | Sign in with Google is enabled | Name, email address, and Google account id | US |
| Plaid Inc. | The workspace connects a bank for a connected product that lists Plaid in its integrations | Account, balance and transaction data the product is configured to read | US |
Connectors are not subprocessors
QuickBooks Online, Xero, HubSpot, Gmail and the rest of the systems a connected product acts in are your processors, not ours. We hold a scoped token; they already hold the data. They appear on a product's integration list, not in the tables above.
Padding this list with the tools you already pay for would make it look thorough and make it useless.
Notice and objection
- 30 days notice, emailed to the workspace owner and posted with a dated changelog, before a new entity processes customer personal data.
- DPA customers may object in writing within 15 days of that notice.
- If we cannot accommodate the objection, you may terminate the affected service before the add date, and prepaid unused platform fees for that remainder are refunded pro rata.
- Removals may be immediate. The changelog is still updated, and at least 24 months of history stays on the page.
04 — DPA / 5 locked positions
The data processing addendum, summarised before you open it.
Click-wrap on Growth and above. Custom paper is a Scale and Enterprise conversation, and there are six clauses counsel does not soften.
- Who signs
- The workspace owner, or your counsel through the request form. Click-wrap on Growth and above; custom paper is an Enterprise conversation.
- Our role
- Processor of run payloads, workspace configuration and audit events. Controller of our own billing records and of website visitor data.
- Your role
- Controller — or processor for your own customers, in which case we are your sub-processor under the same clauses.
- Law
- CCPA/CPRA service-provider terms, plus other US state privacy laws where they apply.
- Processing location
- A Hetzner data center in Nuremberg, Germany, on every tier. No other processing region is offered.
- Breach notice
- Without undue delay and no later than 72 hours after we confirm a personal-data breach.
- Deletion
- Primary deletion within 30 days of termination, backups by day 65. Exceptions: legal hold and tax invoices.
- Audits
- Once a Type II report exists, that report is the default audit. On-site audits and extra questionnaires are an Enterprise MSA term, once per 12 months unless there has been a material incident.
Positions we do not redline
- No training on customer content, by us or by the model subprocessors we route to — written as a DPA exhibit, not only as a website sentence.
- No sale and no share of personal information under CPRA definitions.
- Human approval is the product default where money moves. The DPA does not call model output human reviewed unless a human actually clicked.
- We are a service provider under CCPA. We do not combine your personal information with another customer's to train or profile.
- Redlines that would let us train, drop personal-data breach notice below 72 hours, or add subprocessors without notice are rejected. Everything else is an Enterprise legal conversation.
Data subject requests
A request that reaches us directly is passed to you as controller within 5 business days. We redirect; we do not answer on your behalf.
For requests you handle as controller, the export and deletion tools come first. Manual assistance is inside 15 business days on Scale and above, and 30 on lower plans.
05 — Availability / 4 plans
Two plans carry an availability SLA. The other two carry a support SLA.
Starter and Growth get zero availability credits. What they buy is a response time, and saying so is cheaper than arguing about it later.
| Plan | RPO — data we may lose | RTO — time to restore | Availability SLA |
|---|---|---|---|
| Starter | 24 hours | 8 hours, business hours | None. Best effort, no service credits |
| Growth | 24 hours | 8 hours, business hours | None. Support response SLA only |
| Scale | 1 hour | 4 hours | 99.9% monthly |
| Enterprise | 15 minutes | 1 hour | 99.95% monthly, with credits |
What the percentages mean in minutes
A 30-day month is 30 × 24 = 720 hours = 43,200 minutes. 99.9% allows 0.1% of that, which is 43.2 minutes of unplanned downtime before the SLA is missed. 99.95% allows 21.6 minutes.
Scheduled maintenance in the published window — weekly, two hours, announced 72 hours ahead, typically unused — is excluded from that calculation. It has to be: a single four-hour maintenance called unplanned would burn the Enterprise budget eleven times over. So maintenance is planned, or it counts.
Recovery point objectives follow the same logic. Daily snapshots on Starter and Growth mean a catastrophic zone loss could drop up to one day of unposted drafts — acceptable only because those plans carry no availability SLA. One hour on Scale means we will not ask you to re-key a morning of bills. Fifteen minutes on Enterprise is replica lag we are willing to put in a contract, not a marketing zero.
Backups and disaster recovery
- Continuous write-ahead log shipping for the primary database, plus encrypted snapshots every 24 hours.
- 35-day backup retention, stored in Germany. No backup copies outside it.
- Quarterly restore tests into an isolated account, with the result logged. First test planned for 2026-12-31.
- [PLACEHOLDER: standby and failover for the single Hetzner server — confirm at deployment]
Service credits on Scale and Enterprise
| Monthly uptime | Scale credit | Enterprise credit |
|---|---|---|
| At or above the SLA | 0 | 0 |
| Below the SLA, at or above 99.0% | 10% | 10% |
| Below 99.0%, at or above 98.0% | 25% | 25% |
| Below 98.0% | 50% | 50% |
Credits are capped at 50% of that month’s platform subscription, apply to the subscription rather than to credit overage or one-time licences, are applied to the next invoice rather than wired, and are the sole remedy for availability. Excluded: scheduled maintenance, failures in your own identity provider or OAuth grants, model provider outages we did not cause, self-hosted deployments, and force majeure as defined in the MSA. If our own control plane is down, credits still apply.
Support response times
| Plan | Channel | First response | P1 |
|---|---|---|---|
| Starter | 24 business hours | Same. No 24/7 | |
| Growth | Email and chat | 8 business hours | Same |
| Scale | Named solutions architect, Slack Connect | 4 hours | 1 hour |
| Enterprise | Dedicated CSM and solutions architect | 4 hours | 1 hour, 24/7 |
Business hours are 09:00 to 18:00 US Eastern, Monday to Friday, excluding US federal holidays. P1 means production is down or customer data exposure is suspected. P2 is a single product failing with a workaround available. P3 is a how-to.
06 — Notification / 4 commitments
What we commit to telling you, and when.
The operational detail — detection, containment, the post-incident report — is on the security page. These are the promises.
- Personal-data breach
- Notice to the workspace owner no later than 72 hours after we confirm it. We do not wait for a regulator before telling you.
- P1 security incident, no personal data
- 24 hours from the internal declaration.
- P2 security incident
- 72 hours from the internal declaration.
- Regulators
- Notifying a supervisory authority is your job as controller, and we assist. Where we are controller — website visitors, our own employees — we notify within 72 hours where required.
Availability incidents are posted to the status page. A security breach is not first announced there, and it is not first announced on social media.
07 — Documents / 8 documents
The documents, not a PDF of this page.
A trust portal that is one PDF is not a trust portal. Each of these is a live route; each is currently a draft prepared for counsel review and labelled as such.
- Data processing addendumRoles, subprocessor authorisation, breach clock, and the no-training exhibit.Draft for counsel review
- SubprocessorsThe same table as this page, plus the dated changelog security reviewers compare between snapshots.Draft for counsel review
- Privacy policyWhat we are controller for, what we are processor for, and where model prompts go.Draft for counsel review
- Service level agreementUptime definition, exclusions, the credit table, and the claim procedure.Draft for counsel review
- Acceptable use policyIncluding the prohibition on protected health information until a BAA exists.Draft for counsel review
- Cookie policyStrictly necessary cookies only. No advertising cookies, no cross-site pixels on the app.Draft for counsel review
- Terms of serviceConfidentiality, security standard, suspension, and the export and deletion clock.Draft for counsel review
- Security disclosureCoordinated disclosure rules, scope, and safe harbour.Draft for counsel review
Report PDFs, once any exist, go behind an NDA rather than onto a marketing page. Live availability is at the status page, and the technical control detail is on the security page.
Next step
Send us the questionnaire you were handed.
Ask for the DPA, the subprocessor list, or written answers to a spreadsheet. If your MSA needs a person on a call, book one instead.
Nothing on this page is a certification. Everything on it is dated.
