SECURITY
What protects your data, and what does not yet.
Written for the person who has to fill in a supplier questionnaire about us. Every measure below is in force today. The section near the end lists what we cannot tick — because a page that only lists strengths tells you nothing.
Last updated 17 August 2026
What this document is
A description of the measures actually in place, at the date above. It is not a certificate and it is not an audit. Nobody has inspected us and issued a badge. What it is instead is a straight answer to the questions a careful buyer asks, written so that you can check the claims against what the product visibly does.
If your process needs a completed questionnaire, a data processing agreement or a signed answer to a specific control, ask through the contact form and you will get one.
Where the data sits
Accounts, projects, invoices, enquiries and the systems you build all live in the European Union — the Frankfurt region. Not "the EU where possible": the platform is provisioned there and there is no other copy.
There is one exception and it matters. When the AI writes something for you, the text you gave it is processed by the model provider, and that processing may happen outside the European Economic Area. Those transfers run on the European Commission's standard contractual clauses. If the AI never sees a piece of data, it never leaves.
In transit, and at rest
- Every connection is encrypted. The site, the platform and the API are HTTPS only; plain HTTP is redirected before anything is sent. There is no unencrypted channel to use by mistake.
- Passwords are never stored. What we store is a scrypt hash with a random per-account salt, compared in constant time. Nobody here — including whoever holds the database — can read your password back out. If you sign in with Google there is no password at all, only the account identifier Google gives us.
- Your sign-in token is signed. It is checked on every single request, not only when you log in; altering one character of it invalidates it, and it expires on its own.
- The database is managed for us by our infrastructure provider, in the same Frankfurt region, reachable only over TLS. It is continuously backed up and can be restored to an earlier point in time.
Who can reach it
Customers are separated by construction, not by a filter someone remembered to apply: each customer gets their own project and their own prepaid balance. There is no shared workspace where one account could see another's rows.
The administration panel is on an address that is not linked from anywhere on this site, behind its own login, with a session shorter than a customer's. The credentials that let us talk to the infrastructure behind the platform never reach a browser: every privileged call is made from the server, so there is nothing in the page for a visitor to find.
One door is worth naming, because most suppliers do not name it. From the admin panel we can open your studio — that is how support gets done without asking you to paste screenshots at us. We do it to help you, not to browse. See also the gap we list about logging, below: we would rather tell you the door exists than let you assume it does not.
Payments
Card details never touch our systems. Payment happens on Stripe's own hosted page; we receive a reference, an amount and whether it worked.
Every payment notification Stripe sends us is signature-checked before it is believed, with a constant-time comparison — a forged "payment succeeded" cannot credit an account. Credit transfers are keyed on the payment's own identifier, so a message that arrives twice credits you once. This is the part of the system most worth attacking, and it is the part written most carefully.
The voice consultant
Vera is on public pages with no login in front of her, which makes her a spending target as much as a privacy question. Both are handled.
- No audio is recorded and no transcript is kept. Your microphone audio is processed to produce the reply and is gone. The transcript you see exists in your browser and dies with the panel.
- What we keep is one line per conversation — when, which language, which page, what it cost, why it ended — so that nobody can run up an unlimited bill. Your IP address is stored as a one-way hash we cannot reverse, never as an address.
- Conversations are capped: five minutes each, three per visitor per day, and a ceiling across the whole site per day.
What you build stays yours
The systems you build and the data you put into them belong to you. We do not read them, mine them, or use them to train anything. Details of what we hold and for how long are in the privacy policy.
Who else is involved
Four parties, each getting the minimum it needs and none of them free to use it for their own purposes:
- Our platform and AI infrastructure provider — runs the studio, the hosting and the AI itself. They are named in the data processing agreement, and their terms of use are public, so you can read the obligations we sit under rather than only the ones we quote to you. What they bar, we bar.
- Stripe — takes the payment and holds the card details.
- Google — signs you in if you choose that button, and serves the fonts this site uses.
- Amazon Web Services — the hosting underneath all of it, in Frankfurt.
If we change who processes personal data, business customers are told before it takes effect, not after.
If something goes wrong
If a breach affects your data we will tell you without undue delay and in any case within 72 hours of becoming aware of it, with what happened, which data is affected, what it likely means for you and what we are doing about it.
One honest caveat about that clock. Where the incident is inside our infrastructure provider's systems rather than ours, our 72 hours start when they tell us. We cannot promise you a deadline shorter than the one we have upstream — and any supplier who does promise it either has not thought about it or is not going to keep it.
What we do not have yet
The list a questionnaire will ask for and we cannot tick. It is here so you can decide with your eyes open rather than discover it during procurement.
- No certification of our own. ISO/IEC 27001 and SOC 2 exist in this stack, but they belong to the cloud underneath us. They are not ours and we will not imply otherwise.
- No two-factor authentication on accounts yet. Passwords are hashed properly and Google sign-in is available, which is stronger than most passwords — but a second factor is not there today. It is the next thing we want to build.
- No 24/7 monitoring desk and no guaranteed response time. We are a small team in one timezone. If you need a contractual response window, ask before you sign, not after.
- No independent penetration test report. Nobody has been paid to attack us and write it up.
- No separate operator action log. Credit movements leave a permanent ledger entry behind every account, but administrative actions are not yet written to their own tamper-evident log. This is the gap we would close first.
- Backups are not yet drill-tested. The database is continuously backed up and point-in-time restore is available; we have not yet had to use it in anger, and a restore you have never rehearsed is a plan, not a capability.
- No appointed data protection officer. The scale of what we process does not require one under the GDPR. If your own rules require your suppliers to have one, raise it before contracting.
If you are a regulated buyer
We are not ourselves an entity in scope of NIS2, and we do not claim to be. We can be your supplier, in which case vetting us is part of your own obligation, and we will help you do it: complete your questionnaire, sign a data processing agreement, and take on contractual notification duties.
What we will not do is accept an obligation towards you that we do not hold towards our own provider. A promise nobody upstream is bound to is worth nothing on the day you need it.
Where a system you build here makes or supports decisions about people, the terms set out what may not be built on this platform at all, and where the line falls. The AI Act page sets out which of those duties are ours and which are yours, on the deadlines as they stand today.
Reporting something
Security questions, questionnaires and vulnerability reports all go through the contact form — say it is a security matter in the first line and it jumps the queue.
If you find a hole and tell us in good faith, we will thank you and fix it. We will not pursue you for finding it, provided you did not use it to reach other people's data, degrade the service, or hold it over us.