Security
Controls that are switched on in the product right now.
Single sign-on
SAML 2.0 and OpenID Connect (with PKCE) for Okta, Microsoft Entra ID, Google and others. Signatures verified on every sign-in. Optional enforce-SSO per email domain, with a break-glass administrator so an IdP outage never locks a customer out.
SCIM 2.0 provisioning
Your IdP creates, updates and deactivates accounts automatically. Deprovisioning disables access at once. Administrator accounts cannot be changed over SCIM.
Two-step verification
Email one-time codes for password sign-in, with an organization policy to require it for everyone. SSO sign-ins use your IdP's MFA.
Roles and permissions
Per-Buddy view, edit and approve permissions, plus dedicated roles such as Spend Approver. Spend never moves without a person who holds that role.
Tamper-evident audit log
One append-only log across every Buddy. Each event is chained to the one before it with SHA-256, so edits and deletions are detectable. 600 events recorded; chain verified intact.
Encryption and secrets
TLS on every connection. SSO configuration and client secrets encrypted at rest with the application key. API and SCIM tokens stored only as SHA-256 hashes. Passwords hashed with bcrypt.
Sessions and networks
Configurable idle timeout and an IP allowlist per organization.
Backups
Nightly database backups with rotation. Last run: succeeded.
API with human approval
A documented API and an MCP endpoint for outside agents, with scoped, expiring tokens and rate limits. Anything an agent writes becomes a draft a person approves.
Privacy and data
Data is hosted in the United States (Ashburn, Virginia). Each client's data is separated by tenant in every table. We do not use client data to train AI models.
| Data | Kept for |
|---|---|
| Audit log | 2,555 days, deleted automatically |
| API request log | 90 days, deleted automatically |
| Sign-in events | 365 days, deleted automatically |
| Status samples | 400 days, deleted automatically |
| AI prompt and output log | 90 days, deleted automatically |
| Trust Center requests | 730 days, deleted automatically |
| Data subject export files | 30 days, deleted automatically |
| Buddy chat threads (Data, Campaign, Media, Sales Buddy) | For the life of the contract, or until you ask us to delete it |
| Shopper leads and coupon claims | For the life of the contract, or until you ask us to delete it |
| Media delivery and invoices | For the life of the contract, or until you ask us to delete it |
| Creative assets and renders | For the life of the contract, or until you ask us to delete it |
Access and erasure requests (GDPR, CCPA and similar) are handled through a tracked workflow with identity verification and a 30-day deadline.
Responsible AI
Parts of this work were drafted with AI and reviewed by a person before use.
People approve
A person approves every AI output before it is used.
Model registry
Each Buddy's model, purpose and the data it sends are recorded. Providers in use: Anthropic, Google.
Content credentials
AI-made images carry C2PA Content Credentials on export by default.
Prompt logging
Prompts and outputs are not logged by default; a client can switch logging on for review.
Subprocessors
Companies that process data on our behalf. Last reviewed Oct 5, 2026.
| Company | Purpose | Data | Location |
|---|---|---|---|
| Hetzner Online GmbH | Application and database hosting (dedicated servers) | All customer data at rest and in processing | Ashburn, Virginia, US |
| Anthropic, PBC | AI language model (Buddy chat, planning, copy) | Prompts and Buddy context sent per request | United States |
| OpenAI, L.L.C. | AI image generation | Image prompts and reference images | United States |
| Google LLC | AI models (Gemini), Google APIs (Analytics, Tag Manager read-only) | Prompts; analytics account data when connected | United States |
| Resend, Inc. | Transactional email delivery | Recipient email address and message content | United States |
| Features & Labels, Inc. (fal.ai) | AI image and video generation | Creative prompts and reference media | United States |
| Tavily | Web search for research features | Search queries (no personal data by design) | United States |
Compliance
SOC 2 Type I Not yet audited
Our controls are mapped to the Trust Services Criteria and many are live in the product (above). An independent audit has not happened yet. Ask for the control map and security questionnaire answers below.
Policies On request
Data retention and responsible-AI rules are published on this page from live settings. Information security, access control, incident response and vendor management policies are being formalised for the audit.
Uptime Live
Current status and history are public at /status. Measured every minute by the platform itself.
Request security documentation
Tell us who you are and we will follow up personally. Documents are shared under NDA.