Enterprise Security
Enterprise-grade security built into every layer — so your supply chain data stays yours.
How we protect your data
Multiple independent security layers across every surface of the platform.
Data Encryption
- TLS 1.3 in transit — HTTPS enforced everywhere
- Enterprise-grade encryption at rest for all files and records
- Backup data encrypted across secure cloud infrastructure
Access Control
- MFA available for all accounts
- Principle of least privilege enforced at infrastructure level
- Automatic session timeout and strong password requirements
Data Isolation
- Your data is completely isolated from other users
- Every file, analysis, and conversation tied to your unique user ID
- Database rules enforce strict user ownership at the infrastructure layer
- Separate storage paths per user — no cross-user access possible
Monitoring & Logging
- 24/7 automated threat detection and alerting
- DDoS protection, WAF rules, and rate limiting
Your data, your control
All AI processing happens inside our secure infrastructure — never shared, never sold, never used for training.
Security for every plan
Strong defaults for all users, with advanced controls for Pro and Enterprise.
All Users
- Encrypted data transmission (TLS 1.3)
- Secure authentication
- Automatic session timeout
- Password strength requirements
- Email verification
Advanced Controls
- Multi-factor authentication (MFA)
- Dedicated security support
- Security incident notifications
- Custom data processing agreements
- On-premise deployment (Enterprise)
Data retention & deletion
Clear policies so you always know what we hold and how to remove it.
How long we keep data
Your control
You can delete your data at any time — no lock-in, no friction.
- Delete individual files and analyses
- Clear your entire conversation history
- Export all data before deletion (GDPR right)
- Full account deletion on request
How we respond to incidents
A structured 6-step process ensures rapid containment, transparent communication, and lasting remediation.
Third-party service security
Every partner is vetted against enterprise security standards before integration.
| Service Type | Purpose | Security Standard |
|---|---|---|
| Cloud Infrastructure | Hosting & compute | Enterprise-grade security |
| Authentication | User identity | Industry-standard protocols |
| Database | Data storage | Encrypted, managed service |
| Payment Processing | Subscriptions | PCI DSS Level 1 (Stripe) |
| Email Delivery | Notifications | Secure, managed service |
Compliance & privacy
Built to meet global regulatory requirements from day one.
- Right to access your data
- Right to delete your data
- Right to data portability
- Transparent data processing
- Security & availability controls
- Independent third-party audit
- Continuous compliance monitoring
- Level 1 compliant processing
- No credit card data stored
- All payment data tokenized
Continuous improvement
Security is not a one-time effort — it's an ongoing practice.
Questions about security?
If you have specific security requirements or questions not covered here, our team is ready to help.
Last updated: May 2026 · v1.0