Security & data trust

Your data, handled like it's ours.

If you're going to let someone into your business's numbers, you should know exactly where they're stored, who can see them, and what happens when you leave. No jargon, no certification cosplay — here's how it actually works.

How it works

The practices behind the trust.

Plain answers about how your data and access are actually handled — not a wall of badges.

Per-client isolation

Every client's data lives in its own walled-off scope, enforced at the database level with row-level security. Working in one account can never expose another — no shared tables, no shared keys.

Encrypted in transit and at rest

Everything moves over TLS and is encrypted at rest on Supabase and AWS. Any credentials a build needs are stored scoped to your account and owner-only — never pooled into a shared global account.

Least access, by default

I ask only for the access a task actually needs, prefer read-only where a provider allows it, and use OAuth instead of long-lived keys wherever possible. Admin keys never touch the browser.

One AI vendor for your data: Anthropic

Every AI step that touches your business data runs on Anthropic's Claude models, under their commercial API terms — not fanned out across a rotating cast of providers.

Your data is never training data

Anthropic's commercial API does not train its models on the inputs or outputs we send. Your data is processed to do your work, and nothing else.

No embeddings, no shadow copies

Some tools quietly turn your documents into a permanent vector database that outlives the original. We don't. There are no embeddings and no hidden second copy of your data.

Built on trusted infrastructure

Your portal runs on Supabase and Amazon Web Services — SOC 2 Type II–certified infrastructure with managed, automated backups. (That certification is the infrastructure's, not a badge I claim for myself.)

You own your outputs

Your data, dashboards, and the results we produce are yours, exportable in full at any time. There's no minimum term — if you cancel, you can export everything within 30 days. I maintain the platform; you own everything it produces for you.

Deletion that actually deletes

When you ask me to delete something or close your account, it's removed from the database and file storage — not just hidden — and rolls out of backups on their normal cycle.

Locked-down operator access

The only person who can reach your data is me, the operator running your account — no team, no shared logins, no third-party staff with a key to your numbers. My login is protected by app-based two-factor authentication, so a leaked password alone can't open your account.

The trust questions.

Will my data ever be used for, or shared with, your other clients?

No. Each client's data lives in its own isolated scope (enforced by row-level security), is processed only to do your work, and is never used to build or inform another client's work — or to train any AI model. We put that in writing in a mutual NDA.

How is my data handled during the build?

It lives in your own scoped space in our database (encrypted at rest, isolated by row-level security) and is processed transiently through Anthropic's API to do the analysis. Source files you share only briefly touch an encrypted laptop while they're loaded in, then the local copy is deleted. You can export everything at any time.

Where do my call transcripts and notes go, and how long are they kept?

Discovery-call transcripts and notes live in our Google Workspace and are kept only as long as your engagement needs them; raw transcripts are deleted once the notes are captured. They're confidential and never shared with another client.

Which AI provider processes my data?

Anthropic (Claude), through its commercial API. Your business data isn't sent to other model providers. (Public research on a prospect's own website uses separate tools on publicly available information only — never your private portal data.)

Is my data used to train any AI model?

No. Anthropic's commercial API does not train its models on the inputs or outputs we send through it.

Are embeddings or a vector database created from my documents?

No. There is no vector store and there are no embeddings — nothing that turns your data into a second copy that lives on after the original.

How long is my data kept?

Inside your portal, your data lives in your isolated scope until you delete it or leave. At the AI layer, Anthropic retains API traffic only briefly for abuse monitoring and then discards it.

Can anyone else see my data?

Only me, to do your work. Row-level security prevents any other client from ever seeing your data, and there's no other staff or shared login — it's a solo operation.

Where are my files stored, and do they get passed elsewhere?

On Supabase Storage, which runs on AWS. They aren't sold or shared. The only third parties involved are the named subprocessors that make your build run — for example Anthropic for AI and Stripe for billing.

Do deletion requests remove data from backups and third-party systems too?

Yes. Deletes remove your data from the database and storage, backups roll off on their normal schedule, and the related AI traffic is discarded by Anthropic on its retention cycle.

What happens to my data if I cancel?

There's no minimum term. If you cancel, you can export everything within 30 days, after which we hard-delete it from the database and storage; backups age off on their normal cycle.

Will you sign an NDA or Data Processing Addendum?

Yes. Business clients can request a signed mutual NDA and a Data Processing Addendum (DPA) that spell out confidentiality, no cross-client reuse, our subprocessors, and the security measures above.

Have a question I didn't answer?

Ask it directly — I'd rather over-explain how your data is handled than have you wondering.

Book a call