Security First

Your knowledge is valuable. We take security seriously with enterprise-grade protection for all users.

Encryption at Rest

All data stored in our database is encrypted using AES-256 encryption. This includes your documents, URLs, and any extracted content.

Encryption in Transit

All data transmitted between your browser and our servers uses TLS 1.3 encryption. API communications are always HTTPS.

Row-Level Security

PostgreSQL RLS policies ensure complete data isolation. Users can only access data within their organizations and pockets.

API Key Encryption

BYO API keys are encrypted with AES-256-GCM before storage. Keys are decrypted only when making API calls.

Audit Logging

All sensitive operations are logged for compliance. Team plan includes full audit trail with user attribution.

Secure Infrastructure

Hosted on Vercel, Railway, and Supabase with SOC 2 compliance. Regular security updates and monitoring.

Compliance & Policies

Transparent policies to protect your data and privacy.

Data Residency

Data is stored in US-based data centers. Contact us for EU data residency requirements.

Data Retention

You control your data. Delete pockets, sources, or your entire account at any time with immediate effect.

Third-Party Access

We never share your data with third parties. LLM providers only see the context needed for your queries.

Incident Response

We have documented incident response procedures and will notify affected users within 72 hours of any breach.

Our Security Practices

Regular Security Audits

We conduct regular security reviews and penetration testing to identify and address vulnerabilities.

Dependency Monitoring

Automated scanning for vulnerable dependencies with rapid patching of critical issues.

Secure Development

All code changes go through security review. We follow OWASP guidelines for secure development.

Employee Access

Principle of least privilege. Production access is limited and audited. No employee can access your data without authorization.

Security Questions?

If you have security concerns or want to report a vulnerability, please contact us.