What we hold, what we never hold, and how you can check.
Every sentence on this page has evidence behind it, shown on request. Where we are not there yet, we say so.
We hold, for your account
- The contacts you forward to us
- The documents you send, and the dates and amounts read from them
- Messages sent and received through the portal, and the drafts you edited
- Calendar events created in your own calendar, with your consent
We never hold, by design
- Social Security or government ID numbers
- Credit, screening and background results
- Bank, card and payment details; rent, deposit and trust ledgers
- Health information
The database has no place for the right-hand column. Nothing you send us is sold, shared, or used to train any model.
- Encrypted in transit and at rest
- Your data kept apart from every other customer's
- Two-factor sign-in for anyone who can reach production; access reviewed quarterly
- No third-party scripts or trackers in the product
- Every action on a signed trail you can verify
Every read, draft, edit, approval and sign-in lands on an append-only audit trail, including anything done by us. You can export it and verify the signature without our help.
The portal reaches your calendar and your mailbox only through your provider's own consent screen, which you can revoke from your account at any time. We hold no password of yours.
Working toward SOC 2 Type II.
Our controls are designed to the SOC 2 Trust Services Criteria and documented, with every gap owned and dated. The Type I audit is scheduled for early 2027; the Type II report follows the required observation window. We hold no report yet, and we will tell you when we do.
The infrastructure providers we build on hold SOC 2 Type II reports for the layers they run; that covers their infrastructure, not our code, which is why the audit exists. Automated vulnerability and secret scanning runs on every code change, and a manual penetration test precedes Type II. The providers that touch customer data are listed, with what each receives, in the subprocessor list that comes with every agreement.
The one-page security summary and the control map come with every pilot agreement, and are available under NDA on request.
Ask for the security summary.
One page: what we hold, what we never hold, where it runs, and how deletion and incidents work. It comes with every pilot agreement and is available on request.