Compliance & trust

Built for enterprise procurement

Everything your InfoSec team needs in one page: current certifications status, sub-processor snapshot, downloadable legal artefacts, and a direct procurement contact. We don’t claim certifications we don’t hold — programmes in progress are flagged honestly.

Programme status

Targeted dates are best-effort, not commitments.

GDPR

Live

Public DPA, sub-processor list, in-app DSAR tooling, EU-pinned analytics.

AI no-training contracts

Live

OpenAI + Anthropic API / Commercial Terms — customer content is not used to train models.

OpenAI Zero Data Retention

In progress

Application submitted; removes the default 30-day prompt retention window.

Google CASA Tier 2

In progress

Required for Gmail restricted scopes at scale.

SOC 2 Type I

Planned

Targeted within the next two quarters. Controls in build-out with a GRC platform.

SOC 2 Type II

Planned

Follows Type I after a 6-12 month observation window.

ISO 27001

Planned

Targeted alongside SOC 2 Type II for EU enterprise procurement.

Documents & resources

Linkable, shareable. Each artefact is the canonical version — send these URLs directly to your legal or security review.

Sub-processors snapshot

We share data with the 9 sub-processors below, each bound by a DPA under Art. 28 GDPR. The full table with data categories and transfer mechanisms is on Privacy. Machine-readable feed at /api/v1/sub-processors.

Last updated: 2026-05-16

  • ClerkAuthentication, session management, organisation membership.
  • StripeBilling, subscription management, payment processing.
  • OpenAIAI classification, drafting, summarisation, embeddings.
  • AnthropicAI classification, drafting, summarisation.
  • Recall.aiMeeting bot ingest of transcripts.
  • InngestBackground job orchestration. Event payloads carry only IDs.
  • PostHogProduct analytics, in-app event tracking.
  • Google (Gmail, Calendar)Mailbox and calendar access via OAuth, at user direction.
  • Microsoft (Graph, Outlook, Microsoft 365)Mailbox and calendar access via OAuth, at user direction.

Procurement & security review

Need a security questionnaire (SIG / CAIQ), a custom DPA, regional data residency commitments, or a vendor onboarding packet? Email us — we typically respond within one business day.