No marketing, no asterisks. The list below reflects what our architecture and contracts actually guarantee — not what we hope to one day offer.
Security
✓Encryption in transit (TLS 1.2+)
✓Encryption at rest (AES-256)
✓Secure authentication (OAuth + passkeys)
✓Strict access controls & least privilege
✓Regular verified backups
Privacy
✓No AI training on customer data*
✓Data export, anytime
✓Account & memory deletion
✓Data retention controls
Infrastructure
✓Subprocessors publicly disclosed
✓Infrastructure documented
✓Incident response process
Compliance
·GDPR: Designed for compliance
○SOC 2: Not yet certified
○ISO 27001: Not yet certified
* Only claim what our architecture and contracts actually guarantee. Honesty here is more valuable than pretending we're already enterprise-certified.