Answered before you ask
Finish most of an assessment without a call — or rule us out in five minutes instead of week three. About a third of the answers are no.
Still deciding?Ask the people who build it.Are you SOC 2 certified?
No, and no audit is currently in progress. We hold no compliance certifications — not SOC 2, not ISO 27001, not HIPAA. If certification is a requirement, we will not pass your review.How is customer data isolated between tenants?
By Postgres row-level security, applied in the database engine against a session context set once per request — not by a WHERE clause each query is responsible for remembering. A query that omits the filter returns nothing rather than everything, and a caller who guesses another workspace's resource id receives a 404.Is data encrypted at rest and in transit?
Yes to both. TLS on every hop with HSTS on the public surfaces; storage-layer encryption on the database and object storage. Credentials for connected accounts get an additional layer: envelope encryption with a data key belonging to that workspace alone, plus a separate key for fields that must remain searchable.Do you train models on our data?
No. Content your assistant reads and messages your visitors send are used to answer questions and to produce your own analytics. They are not used to train models, by us or by the model providers under the terms we hold with them, and they are not sold.Which subprocessors receive our data?
The full list is published and kept current, split into providers that are always in the path and those that only receive data if you connect them. It names what each one actually receives rather than a one-word purpose. See the subprocessors page.Can we choose where our data is stored?
No. There is a single region and it is not configurable, and model inference happens wherever the provider runs it. If you have a contractual data-residency requirement, we cannot meet it today.Do you support SSO or SAML?
Not yet. Accounts sign in with email and password or with Google, and TOTP two-factor is available. There is no SAML or SCIM. SSO is the most common enterprise request — if it blocks a purchase, say so; that is the signal that gets it built.Do you offer a DPA?
Yes. We act as a processor for the conversation data your visitors generate; you remain the controller. Ask and we will sign one.What is your incident notification commitment?
A public write-up within 72 hours of confirming a customer-affecting security incident, plus direct email to every affected workspace — not just a status page update. The commitments are published in advance on the incidents page, including that entries are never quietly removed.Has a third party penetration tested the product?
No. Everything in the security architecture is our own design and our own review. When an external test is commissioned, the summary will be published on the compliance page.Can we delete our data?
Yes. Workspace data can be deleted, and deletion removes it from the primary database and from object storage.What happens to our data if we stop paying?
The assistant stops answering, and your data remains available to export for a period before deletion. The specifics are in the billing policy, and it is a question worth asking of any vendor before you depend on them.Do you have a vulnerability disclosure process?
Yes, with published commitments — including that we will not pursue legal action for good-faith research, will not require an NDA as a condition of fixing something, and will not silently patch and deny. There is no paid bug bounty and the page says so rather than implying one.Is there an audit log?
Yes. Each workspace has an append-only audit log, and any access to your workspace by our staff is time-boxed, carries a stated reason and is written into that log. Conversations and every tool call, with its outcome, are recorded per workspace too.
Need your own form filled in? Send it to security@integrable.cloud · architecture · subprocessors · data residency