Skip to content

Trust center

Where compliance actually stands, with the dates we are working to.

No certification on this page is held today. SOC 2, ISO 27001 and HIPAA appear here as a dated roadmap, marked Planned, because implying a report we do not have is the one thing a trust page must never do.

Status as of

Certifications held0

On the roadmap4

01 — Compliance / 7 frameworks

Every framework, what it actually is, and whether we hold it.

Two of the rows below are laws, not certifications — there is no certificate to hold for CCPA or HIPAA, and anyone who shows you one is selling something.

Compliance status as of 2026-09-15
FrameworkWhat it actually isStatusWho can see evidence
SOC 2 Type IPoint-in-time report on control designPlanned. Not achieved. A target date, not a commitment that it is done.Target Growth and above under NDA, once issued
SOC 2 Type IIReport on operating effectiveness over an observation windowPlanned. Not achieved. A target date, not a commitment that it is done.Target Growth and above under NDA, once issued. Observation window 2027-06-01 to 2027-11-30
ISO/IEC 27001Certified ISMSPlanned. Not achieved. A target date, not a commitment that it is done.Target Certificate public; Statement of Applicability under NDA on Scale and above
CCPA / CPRALaw, not a certification. We do not sell or share personal information as those terms are definedOperational (not a certification). A legal programme that runs today. Not a certification.Privacy policy
HIPAAThere is no such thing as HIPAA certified. It is a BAA plus safeguards for ePHINot offered. Not available today at any plan level.Target Enterprise only, once live. Acceptable use forbids ePHI until then
Penetration testIndependent annual web and API testPlanned. Not achieved. A target date, not a commitment that it is done.Target Letter of attestation public; full report under NDA on Scale and above
Vulnerability disclosureCoordinated disclosure programmeOperational. A programme that runs today. Not a certification.This page and security.txt

Allowed status values on this page are Held, Operational, Planned and Not offered. Certified is not one of them for CCPA or HIPAA, because it does not exist for either.

02 — Roadmap / 5 dated items

The roadmap, and why each date is where it is.

Controls have to run before an auditor can say they ran. These dates come from that constraint, not from what would look good on a slide.

  1. Milestone 01

    SOC 2 Type I

    Point-in-time report on control design

    Growth and above under NDA, once issued

    Planned. Not achieved. A target date, not a commitment that it is done.Target
  2. Milestone 02

    SOC 2 Type II

    Report on operating effectiveness over an observation window

    Growth and above under NDA, once issued. Observation window 2027-06-01 to 2027-11-30

    Planned. Not achieved. A target date, not a commitment that it is done.Target
  3. Milestone 03

    ISO/IEC 27001

    Certified ISMS

    Certificate public; Statement of Applicability under NDA on Scale and above

    Planned. Not achieved. A target date, not a commitment that it is done.Target
  4. Milestone 04

    HIPAA

    There is no such thing as HIPAA certified. It is a BAA plus safeguards for ePHI

    Enterprise only, once live. Acceptable use forbids ePHI until then

    Not offered. Not available today at any plan level.Target
  5. Milestone 05

    Penetration test

    Independent annual web and API test

    Letter of attestation public; full report under NDA on Scale and above

    Planned. Not achieved. A target date, not a commitment that it is done.Target

How the SOC 2 dates were derived

A Type I report describes control design, so the controls have to be implemented and frozen first. From a design start in September 2026: implement through Q4 2026, freeze in Q1 2027, fieldwork in April 2027, report by 2027-05-31.

A Type II report covers operating effectiveness over an observation window. Six months is the shortest window a serious auditor will sign, which puts the first Type II at 2027-12-15 — not next quarter. ISO 27001 is a full ISMS cycle with its own scope, statement of applicability, internal audit and two-stage certification; the target is a year after the first Type II, not a parallel rush.

What the plans entitle you to

Growth and above may receive the SOC 2 report under NDA when it is issued. Status today: Planned, report target 2027-12-15.

Enterprise may sign a business associate agreement when one is offered, target 2027-06-30. Until that date we do not sign a BAA and protected health information is forbidden in run payloads on every plan.

What is operational today

These are running programmes rather than certificates. The evidence is a document you can read, not a seal.

Programmes operational from launch
ProgrammeWhat it actually isEvidence
CCPA / CPRALaw, not a certification. We do not sell or share personal information as those terms are definedPrivacy policy
Vulnerability disclosureCoordinated disclosure programmeThis page and security.txt

03 — Subprocessors / 6 platform, 3 conditional

Every entity that may touch customer personal data, named.

Model providers are on this list even though buyers below Scale never choose one. If a vendor is not here, we are not allowed to use them on your data.

Platform subprocessors that process customer personal data
Legal entityPurposeData classesProcessing locationContractIn production at launch
Hetzner Online GmbHServer hosting, database, and backupsAccount data, workspace config, connector secrets, run payload, run metadata, audit events, support data, website inquiriesGermany (Nuremberg)Data processing agreement — to conclude before launchYes
Zoho Corporation B.V.Email hosting for our mailboxesEmail you send us and our replies, including support requestsEU (Zoho EU data centers)Data processing addendum — to request before launchYes
Stripe, Inc.Payments, invoices, and tax on our own feesBilling identity, card last four, subscription state. No card number on our sideUSStripe DPANo — checkout records a waitlist and takes no payment
OpenAI, LLCModel inferencePrompt, retrieved context and completion, for products that call a modelUSDPA plus zero-retention or no-training terms where offeredNo — no product in this build calls a model
Anthropic, PBCModel inferencePrompt, retrieved context and completion, when routed thereUSDPA plus no-training or zero-retention terms where offeredNo — no product in this build calls a model
Google LLC (Google Cloud / Vertex AI)Model inferencePrompt, retrieved context and completion, when routed thereUSGoogle Cloud DPANo — no product in this build calls a model

Conditional subprocessors — only if you switch the feature on

Conditional subprocessors, used only when their trigger applies
Legal entityWhat turns it onDataProcessing location
Slack Technologies, LLCA Slack webhook is configured for new-inquiry alertsInquiry details: email, name, company, and the messageUS
Google LLCSign in with Google is enabledName, email address, and Google account idUS
Plaid Inc.The workspace connects a bank for a connected product that lists Plaid in its integrationsAccount, balance and transaction data the product is configured to readUS

Connectors are not subprocessors

QuickBooks Online, Xero, HubSpot, Gmail and the rest of the systems a connected product acts in are your processors, not ours. We hold a scoped token; they already hold the data. They appear on a product's integration list, not in the tables above.

Padding this list with the tools you already pay for would make it look thorough and make it useless.

Notice and objection

  • 30 days notice, emailed to the workspace owner and posted with a dated changelog, before a new entity processes customer personal data.
  • DPA customers may object in writing within 15 days of that notice.
  • If we cannot accommodate the objection, you may terminate the affected service before the add date, and prepaid unused platform fees for that remainder are refunded pro rata.
  • Removals may be immediate. The changelog is still updated, and at least 24 months of history stays on the page.

04 — DPA / 5 locked positions

The data processing addendum, summarised before you open it.

Click-wrap on Growth and above. Custom paper is a Scale and Enterprise conversation, and there are six clauses counsel does not soften.

Who signs
The workspace owner, or your counsel through the request form. Click-wrap on Growth and above; custom paper is an Enterprise conversation.
Our role
Processor of run payloads, workspace configuration and audit events. Controller of our own billing records and of website visitor data.
Your role
Controller — or processor for your own customers, in which case we are your sub-processor under the same clauses.
Law
CCPA/CPRA service-provider terms, plus other US state privacy laws where they apply.
Processing location
A Hetzner data center in Nuremberg, Germany, on every tier. No other processing region is offered.
Breach notice
Without undue delay and no later than 72 hours after we confirm a personal-data breach.
Deletion
Primary deletion within 30 days of termination, backups by day 65. Exceptions: legal hold and tax invoices.
Audits
Once a Type II report exists, that report is the default audit. On-site audits and extra questionnaires are an Enterprise MSA term, once per 12 months unless there has been a material incident.

Positions we do not redline

  • No training on customer content, by us or by the model subprocessors we route to — written as a DPA exhibit, not only as a website sentence.
  • No sale and no share of personal information under CPRA definitions.
  • Human approval is the product default where money moves. The DPA does not call model output human reviewed unless a human actually clicked.
  • We are a service provider under CCPA. We do not combine your personal information with another customer's to train or profile.
  • Redlines that would let us train, drop personal-data breach notice below 72 hours, or add subprocessors without notice are rejected. Everything else is an Enterprise legal conversation.

Data subject requests

A request that reaches us directly is passed to you as controller within 5 business days. We redirect; we do not answer on your behalf.

For requests you handle as controller, the export and deletion tools come first. Manual assistance is inside 15 business days on Scale and above, and 30 on lower plans.

05 — Availability / 4 plans

Two plans carry an availability SLA. The other two carry a support SLA.

Starter and Growth get zero availability credits. What they buy is a response time, and saying so is cheaper than arguing about it later.

Recovery objectives and availability SLA by plan
PlanRPO — data we may loseRTO — time to restoreAvailability SLA
Starter24 hours8 hours, business hoursNone. Best effort, no service credits
Growth24 hours8 hours, business hoursNone. Support response SLA only
Scale1 hour4 hours99.9% monthly
Enterprise15 minutes1 hour99.95% monthly, with credits

What the percentages mean in minutes

A 30-day month is 30 × 24 = 720 hours = 43,200 minutes. 99.9% allows 0.1% of that, which is 43.2 minutes of unplanned downtime before the SLA is missed. 99.95% allows 21.6 minutes.

Scheduled maintenance in the published window — weekly, two hours, announced 72 hours ahead, typically unused — is excluded from that calculation. It has to be: a single four-hour maintenance called unplanned would burn the Enterprise budget eleven times over. So maintenance is planned, or it counts.

Recovery point objectives follow the same logic. Daily snapshots on Starter and Growth mean a catastrophic zone loss could drop up to one day of unposted drafts — acceptable only because those plans carry no availability SLA. One hour on Scale means we will not ask you to re-key a morning of bills. Fifteen minutes on Enterprise is replica lag we are willing to put in a contract, not a marketing zero.

Backups and disaster recovery

  • Continuous write-ahead log shipping for the primary database, plus encrypted snapshots every 24 hours.
  • 35-day backup retention, stored in Germany. No backup copies outside it.
  • Quarterly restore tests into an isolated account, with the result logged. First test planned for 2026-12-31.
  • [PLACEHOLDER: standby and failover for the single Hetzner server — confirm at deployment]

Service credits on Scale and Enterprise

Service credits by monthly uptime
Monthly uptimeScale creditEnterprise credit
At or above the SLA00
Below the SLA, at or above 99.0%10%10%
Below 99.0%, at or above 98.0%25%25%
Below 98.0%50%50%

Credits are capped at 50% of that month’s platform subscription, apply to the subscription rather than to credit overage or one-time licences, are applied to the next invoice rather than wired, and are the sole remedy for availability. Excluded: scheduled maintenance, failures in your own identity provider or OAuth grants, model provider outages we did not cause, self-hosted deployments, and force majeure as defined in the MSA. If our own control plane is down, credits still apply.

Support response times

Support channels and response times by plan
PlanChannelFirst responseP1
StarterEmail24 business hoursSame. No 24/7
GrowthEmail and chat8 business hoursSame
ScaleNamed solutions architect, Slack Connect4 hours1 hour
EnterpriseDedicated CSM and solutions architect4 hours1 hour, 24/7

Business hours are 09:00 to 18:00 US Eastern, Monday to Friday, excluding US federal holidays. P1 means production is down or customer data exposure is suspected. P2 is a single product failing with a workaround available. P3 is a how-to.

06 — Notification / 4 commitments

What we commit to telling you, and when.

The operational detail — detection, containment, the post-incident report — is on the security page. These are the promises.

Personal-data breach
Notice to the workspace owner no later than 72 hours after we confirm it. We do not wait for a regulator before telling you.
P1 security incident, no personal data
24 hours from the internal declaration.
P2 security incident
72 hours from the internal declaration.
Regulators
Notifying a supervisory authority is your job as controller, and we assist. Where we are controller — website visitors, our own employees — we notify within 72 hours where required.

Availability incidents are posted to the status page. A security breach is not first announced there, and it is not first announced on social media.

07 — Documents / 8 documents

The documents, not a PDF of this page.

A trust portal that is one PDF is not a trust portal. Each of these is a live route; each is currently a draft prepared for counsel review and labelled as such.

Report PDFs, once any exist, go behind an NDA rather than onto a marketing page. Live availability is at the status page, and the technical control detail is on the security page.

Next step

Send us the questionnaire you were handed.

Ask for the DPA, the subprocessor list, or written answers to a spreadsheet. If your MSA needs a person on a call, book one instead.

Nothing on this page is a certification. Everything on it is dated.