Trust Center
Everything your security, privacy, and procurement teams need to say yes: the controls, how we handle data, and every policy in one place.
Built-in controls
Security baked into every workspace
Not an enterprise add-on. These ship with Supportweave from day one.
Audit trail
Every security and account event is logged: who did what, when, with CSV export.
GDPR export & erasure
Per-workspace data export and right-to-be-forgotten delete, built in.
Data retention
Set a per-workspace window; a daily job auto-purges old conversations and messages.
Secrets encrypted at rest
Channel credentials are AES-GCM encrypted at rest and are not exposed to the model or to client-side code.
Enforced 2FA
TOTP two-factor enrollment and an enforced login challenge.
Outbound safety (allow-list)
Outbound agent actions are restricted to destinations you've explicitly allow-listed, with server-side protections on every outbound request.
Tenant isolation
Strict per-workspace tenant isolation across the platform.
Signed webhooks
Inbound provider webhooks are signature-verified; outbound webhooks are HMAC-signed.
Your data stays yours
We don't train foundation models on your content. Channel credentials are encrypted at rest and never exposed to the model. Export or delete your data anytime.
- Data export and erasure tooling that supports GDPR requests
- Per-workspace retention windows with daily auto-purge
- Strict per-tenant isolation between customer workspaces
- DPA & subprocessor list available on request
- Regional deployment available by written agreement
Every policy, one click away
Need a DPA, subprocessor list, or security questionnaire completed? Email help@supportweave.com.