Where it is held
Your data is held in the region you choose. We provision your workspace’s database in that region, and its records, files and backups all stay there.
Who else touches it
Two lists, deliberately kept apart. The first is the one you came for: companies that can hold or see data inside a customer workspace. The second covers the website and our sales process, and touches no workspace at all.
their security page ↗
their trust centre ↗
their security page ↗
Two absences worth stating, because a reviewer will look for them and their absence is otherwise ambiguous: there is no third-party error-monitoring vendor and no separate transactional email vendor — account and invitation email goes through the identity provider above.
Integrations you connect yourself — a work tracker, a document store — are not our sub-processors. They are your own vendors, and data moves to them because you chose to connect them.
HubSpot, Google Analytics, Zoom, Fathom and Google Workspace support the website and our sales conversations, all processing in the United States. None of them touches a customer workspace. They are listed in full in our privacy policy.
The AI question
For a product with an AI assistant this is the first thing anyone asks, so it gets the most space and the most sourcing.
What the audit trail proves
Every governance product claims an audit trail. Almost none of them say what it cannot establish — and a reviewer who finds a limit we did not mention discounts everything we did. So the right-hand column is published on purpose.
How data leaves
Reviewers ask how data gets out because they are really asking whether they can leave.
Your decisions and files are never on a deletion clock. The retention setting above governs the audit log — the record of events — and nothing else.
Notice of change
What we do not publish, and why. Software versions, hostnames, internal architecture and the security tooling we run stay off this page — they answer no question a reviewer actually has, and they tell someone where to knock. Anything a reviewer genuinely needs that is not here — a completed security questionnaire, or a current statement of what we do and do not yet have — we give on request.
Anything unmarked, ask — we would rather answer than have you assume.