Skip to main content

Preparing for public launch. Book a personalized walkthrough

Trust Center

Everything your security, privacy, and procurement teams need to say yes: the controls, how we handle data, and every policy in one place.

Secrets encrypted at rest (AES-GCM)
Enforced 2FA + audit trail
GDPR export & right-to-erasure
Regional deployment by written agreement

Built-in controls

Security baked into every workspace

Not an enterprise add-on. These ship with Supportweave from day one.

Audit trail

Every security and account event is logged: who did what, when, with CSV export.

GDPR export & erasure

Per-workspace data export and right-to-be-forgotten delete, built in.

Data retention

Set a per-workspace window; a daily job auto-purges old conversations and messages.

Secrets encrypted at rest

Channel credentials are AES-GCM encrypted at rest and are not exposed to the model or to client-side code.

Enforced 2FA

TOTP two-factor enrollment and an enforced login challenge.

Outbound safety (allow-list)

Outbound agent actions are restricted to destinations you've explicitly allow-listed, with server-side protections on every outbound request.

Tenant isolation

Strict per-workspace tenant isolation across the platform.

Signed webhooks

Inbound provider webhooks are signature-verified; outbound webhooks are HMAC-signed.

Your data stays yours

We don't train foundation models on your content. Channel credentials are encrypted at rest and never exposed to the model. Export or delete your data anytime.

  • Data export and erasure tooling that supports GDPR requests
  • Per-workspace retention windows with daily auto-purge
  • Strict per-tenant isolation between customer workspaces
  • DPA & subprocessor list available on request
  • Regional deployment available by written agreement

Security questions? We're an open book.

Get the trust details your team needs to say yes.