Security

What we actually protect, and what we don't yet — no fine print.

We'd rather tell you the real limits than promise something that doesn't exist yet.

Per-account data isolation

Every business lives in its own compartment at the database level (Row-Level Security). One customer's data can never mix with another's, no matter what path is used to request it.

The AI never invents prices

Every quote comes from your real catalog, never from what the language model "thinks" something costs. If you mark a product "quote on request," the AI can talk about it but never closes the sale on its own.

Human control at every step

You can turn on manual approval before any reply goes out, and you can always step into a conversation yourself — the AI steps aside the moment you do.

Encrypted secrets, never in plain text

Integration credentials and webhook secrets are stored encrypted in the database, not in plain text.

What we don't have yet

  • There's no formal uptime SLA yet — we won't promise you an availability percentage we can't actually measure.
  • Database backups run daily, not in real time — worst case if something breaks, you could lose up to 24 hours of data, not your whole history.
  • We don't have an external certification (SOC 2, ISO 27001) yet — today's security lives in the architecture and practices described above, not in a third-party auditor's seal.

Deeper technical questions?

The full AI harness architecture is documented for developers.

View technical docs