We use cookies to enhance your experience and measure how the site performs. Choose "Essential Only" to disable analytics. Read our Privacy Policy.

    Trust Center

    How we handle your data.

    Direct answers for your compliance officer, your CISO and your data-protection lead. If you need anything in writing, we have a DPA template — just ask.

    Encryption everywhere

    TLS 1.3 in transit. AES-256 at rest. Database, file storage and search indices are all encrypted by default. No exceptions.

    UK + EU data residency

    Production data is hosted in UK and EU regions. We do not move customer data outside the UK/EU without an explicit contractual agreement.

    No training on your data

    We do not use customer prompts, documents, knowledge or outputs to train our own models. Your data trains nothing. Period.

    Role-based access

    Customer-tenant isolation at the database row level. Internal access is audit-logged and limited to named on-call engineers for incident response only.

    Retention you control

    Workspaces, conversations and uploaded files are retained for the duration of your contract. You can delete content at any time; deletion is propagated within 30 days across primary + backup storage.

    GDPR-ready

    We act as data processor for customer data and as controller for the limited operational logs we keep. DPA available on request; subject access request workflow documented.

    Certifications

    Where we are on the roadmap.

    We're transparent about what we have and what we're working on. Anything below in “In progress” or “Planned” is on an active timeline; ask for a specific target date.

    Cyber Essentials Certified

    Target Q3 2026.

    In progress

    ISO 27001:2022

    Targeted for late 2026.

    Planned

    SOC 2 Type II

    For enterprise tier customers.

    Planned

    Sub-processors

    Who else touches data we hold.

    The third parties we use in production, what they do, where they run, and whether we have a Data Processing Agreement in place.

    ProviderPurposeRegionDPA
    AnthropicLLM inference (Claude family)EU/UK routedYes
    OpenAILLM inference (fallback models)EU routedYes
    AWSCloud infrastructureeu-west-2 (London)Yes
    CloudflareCDN, DNS, DDoS protectionEU edgeYes
    SanityMarketing site CMS (not customer data)EUYes
    SentryError monitoringEUYes
    PostHogProduct analytics (anonymised)EUYes
    Cal.comDemo scheduling (not customer data)EUYes

    We notify customers in writing 30 days before adding a new sub-processor that handles customer data.

    Need this in writing?

    We have a Data Processing Agreement template, an internal security questionnaire, and we're happy to walk through any of it on a call.

    Email security