Skip to main content

Security & data handling

Your data boundary comes first.

Agree on the source, access and lifecycle before client data enters a workspace. Each safeguard must be verified for the exact deployment and source path your workspaces use.

Four operating commitments

The prepared demo uses illustrative records and connects to no provider or customer account.

Workspace access

Server-side organization permissions and restricted database roles protect workspace boundaries. Founder support access must be necessary, permission-controlled, logged and revocable.

Connections stay off by default

Provider, email, webhook, analytics and paid API traffic remain off by default. A credential does not authorize a source connection.

A defined data lifecycle

The order form defines export, disconnect, retention, deletion, backup expiry and completion evidence before client data is accepted.

A human owns the recommendation

Observed evidence, interpretation, forecast and recommendation remain distinct. A named reviewer approves every client-facing brief.

Before you start

Write down the operating details.

These are items to agree and verify before payment, not a claim that an unspecified deployment is ready.

See current source availability
  1. 01

    Data & source scope

    Name permitted records, the source account, workspace owners, subprocessors, the retention window and prohibited data.

  2. 02

    Operational readiness

    Verify the access-controlled deployment, database restore, migration recovery, source sandbox, incident path, observability and cost limits.

  3. 03

    Exit & accountability

    Agree on contacts, support hours, export format, credential revocation, deletion timing, backup expiry and completion evidence.

  4. 04

    Qualified contract review

    Review privacy, service, data-processing, acceptable-use, retention, subprocessor and incident terms before payment.

Review the data scope before you start.

A written agreement should make access, retention, deletion, support and incident responsibilities clear for your organisation.

Request access