We hold no compliance certifications yet
Not SOC 2, not ISO 27001, not HIPAA. If your procurement process requires one, we won’t pass it — and the useful thing is to say so in the first paragraph rather than the fortieth minute.
Status
Certifications and practices, one by one
- SOC 2 Type IINoNot yetNot certified and no audit is in progress. If your procurement process requires it, we will not pass, and we would rather say so now than in week six.
- HIPAANoNot yetNot certified, and we do not sign BAAs. Do not put protected health information into an assistant here.
- ISO 27001NoNot yetNot certified.
- GDPR — data processing termsPartlyIn partA DPA is available and the subprocessor list is published. We are a processor for the conversation data your visitors generate; you remain the controller.
- Data deletion on requestYesYesWorkspace data can be deleted, and deletion removes it from the primary database and object storage.
- Encryption in transitYesYesTLS everywhere, with HSTS on the public surfaces.
- Encryption at restYesYesAt the storage layer, plus per-workspace envelope encryption for connected-account credentials specifically.
- Penetration test reportNoNot yetNo third-party test has been commissioned yet. When one is, the summary will be published here.
Going forward
What happens when this changes
Certification follows demand
An audit is a real cost at this stage. If a certification is blocking a deal, tell us — that is the signal that changes the calculation.
Announced when real, not before
When an audit starts, this page says so with the scope and expected date. A penetration test summary is published here when one happens.