Trust center
Everything your legal and security teams will ask for
One page with the whole pack: the agreement you already have, the vendors who see your data, how long we keep it, and how to report a problem. Nothing here is behind a sales call.
Documents
The pack, in full
Each one is a real document, not a summary that ends in a contact form.
Roles, subject matter, Article 28(3) obligations, EU SCCs Modules Two and Three, the UK Addendum, the Swiss adaptations, and a contractual 72-hour breach-notification commitment.
In force automatically. Counter-signature on request.
Subprocessor listEvery third party that processes personal data for us, with purpose, data categories, processing region and transfer mechanism.
16 named entries, 30 days' notice before any change.
Security practicesWhat is encrypted at the application layer, what relies on encrypted infrastructure volumes, how access is scoped, and what the audit log records.
Written to be checkable, not impressive.
Vulnerability disclosureScope, safe harbour for good-faith research, response times, and how to reach the engineer who will fix it.
Acknowledged in 3 business days, triaged in 10.
Retention matrixThe default retention period for each class of data we hold, whether it is configurable, and the code path that enforces it.
13 data classes, with real numbers.
Cookie policyEvery cookie and browser-storage entry, its purpose, its duration and its category. No advertising or cross-site tracking storage.
10 entries, all listed.
Privacy policyWhat we process and why, AI-assisted processing, international transfers, and US state privacy rights including CCPA and CPRA.
Covers candidates as well as workspace members.
Terms of serviceAccounts, subscriptions, acceptable use, AI-assisted output, liability, and a concrete governing law for self-serve customers.
No blank order-form reference.
What we do not claim
The gaps, named by us before you find them
A certification we do not hold is worth nothing to you and everything to a procurement review that catches us overstating it.
- No SOC 2 Type I or Type II report, and no ISO 27001 certificate. We do not hold either, so there is nothing to request under NDA.
- No third-party penetration test report. We have not commissioned one yet.
- No single sign-on or SCIM directory sync. Neither ships today.
- No bug bounty payments. We credit researchers publicly; we do not pay.
- No dedicated intrusion-detection or breach-detection tooling. The 72-hour notification commitment in the DPA is a contractual undertaking; what would surface an incident today is operational alerting and the audit log, not a security monitoring product.
- No independently evidenced flow-down agreements with subprocessors. Each is engaged under its own published DPA; we have not collected and published counterparties for review.