The Buddy System

Trust Center

How The Buddy System protects your data, governs its AI, and stays up. Everything on this page is generated from the platform's live settings, so it says what is true today, including what is not done yet.

Platform degraded 100% uptime over 30 days (self-measured)

Security

Controls that are switched on in the product right now.

Single sign-on

SAML 2.0 and OpenID Connect (with PKCE) for Okta, Microsoft Entra ID, Google and others. Signatures verified on every sign-in. Optional enforce-SSO per email domain, with a break-glass administrator so an IdP outage never locks a customer out.

SCIM 2.0 provisioning

Your IdP creates, updates and deactivates accounts automatically. Deprovisioning disables access at once. Administrator accounts cannot be changed over SCIM.

Two-step verification

Email one-time codes for password sign-in, with an organization policy to require it for everyone. SSO sign-ins use your IdP's MFA.

Roles and permissions

Per-Buddy view, edit and approve permissions, plus dedicated roles such as Spend Approver. Spend never moves without a person who holds that role.

Tamper-evident audit log

One append-only log across every Buddy. Each event is chained to the one before it with SHA-256, so edits and deletions are detectable. 600 events recorded; chain verified intact.

Encryption and secrets

TLS on every connection. SSO configuration and client secrets encrypted at rest with the application key. API and SCIM tokens stored only as SHA-256 hashes. Passwords hashed with bcrypt.

Sessions and networks

Configurable idle timeout and an IP allowlist per organization.

Backups

Nightly database backups with rotation. Last run: succeeded.

API with human approval

A documented API and an MCP endpoint for outside agents, with scoped, expiring tokens and rate limits. Anything an agent writes becomes a draft a person approves.

Privacy and data

Data is hosted in the United States (Ashburn, Virginia). Each client's data is separated by tenant in every table. We do not use client data to train AI models.

DataKept for
Audit log2,555 days, deleted automatically
API request log90 days, deleted automatically
Sign-in events365 days, deleted automatically
Status samples400 days, deleted automatically
AI prompt and output log90 days, deleted automatically
Trust Center requests730 days, deleted automatically
Data subject export files30 days, deleted automatically
Buddy chat threads (Data, Campaign, Media, Sales Buddy)For the life of the contract, or until you ask us to delete it
Shopper leads and coupon claimsFor the life of the contract, or until you ask us to delete it
Media delivery and invoicesFor the life of the contract, or until you ask us to delete it
Creative assets and rendersFor the life of the contract, or until you ask us to delete it

Access and erasure requests (GDPR, CCPA and similar) are handled through a tracked workflow with identity verification and a 30-day deadline.

Responsible AI

Parts of this work were drafted with AI and reviewed by a person before use.

People approve

A person approves every AI output before it is used.

Model registry

Each Buddy's model, purpose and the data it sends are recorded. Providers in use: Anthropic, Google.

Content credentials

AI-made images carry C2PA Content Credentials on export by default.

Prompt logging

Prompts and outputs are not logged by default; a client can switch logging on for review.

Subprocessors

Companies that process data on our behalf. Last reviewed Oct 5, 2026.

CompanyPurposeDataLocation
Hetzner Online GmbHApplication and database hosting (dedicated servers)All customer data at rest and in processingAshburn, Virginia, US
Anthropic, PBCAI language model (Buddy chat, planning, copy)Prompts and Buddy context sent per requestUnited States
OpenAI, L.L.C.AI image generationImage prompts and reference imagesUnited States
Google LLCAI models (Gemini), Google APIs (Analytics, Tag Manager read-only)Prompts; analytics account data when connectedUnited States
Resend, Inc.Transactional email deliveryRecipient email address and message contentUnited States
Features & Labels, Inc. (fal.ai)AI image and video generationCreative prompts and reference mediaUnited States
TavilyWeb search for research featuresSearch queries (no personal data by design)United States

Compliance

SOC 2 Type I Not yet audited

Our controls are mapped to the Trust Services Criteria and many are live in the product (above). An independent audit has not happened yet. Ask for the control map and security questionnaire answers below.

Policies On request

Data retention and responsible-AI rules are published on this page from live settings. Information security, access control, incident response and vendor management policies are being formalised for the audit.

Uptime Live

Current status and history are public at /status. Measured every minute by the platform itself.

Request security documentation

Tell us who you are and we will follow up personally. Documents are shared under NDA.