Security First
Your knowledge is valuable. We take security seriously with enterprise-grade protection for all users.
Encryption at Rest
All data stored in our database is encrypted using AES-256 encryption. This includes your documents, URLs, and any extracted content.
Encryption in Transit
All data transmitted between your browser and our servers uses TLS 1.3 encryption. API communications are always HTTPS.
Row-Level Security
PostgreSQL RLS policies ensure complete data isolation. Users can only access data within their organizations and pockets.
API Key Encryption
BYO API keys are encrypted with AES-256-GCM before storage. Keys are decrypted only when making API calls.
Audit Logging
All sensitive operations are logged for compliance. Team plan includes full audit trail with user attribution.
Secure Infrastructure
Hosted on Vercel, Railway, and Supabase with SOC 2 compliance. Regular security updates and monitoring.
Compliance & Policies
Transparent policies to protect your data and privacy.
Data Residency
Data is stored in US-based data centers. Contact us for EU data residency requirements.
Data Retention
You control your data. Delete pockets, sources, or your entire account at any time with immediate effect.
Third-Party Access
We never share your data with third parties. LLM providers only see the context needed for your queries.
Incident Response
We have documented incident response procedures and will notify affected users within 72 hours of any breach.
Our Security Practices
Regular Security Audits
We conduct regular security reviews and penetration testing to identify and address vulnerabilities.
Dependency Monitoring
Automated scanning for vulnerable dependencies with rapid patching of critical issues.
Secure Development
All code changes go through security review. We follow OWASP guidelines for secure development.
Employee Access
Principle of least privilege. Production access is limited and audited. No employee can access your data without authorization.
Security Questions?
If you have security concerns or want to report a vulnerability, please contact us.