Skip to content

Certifications

Certified and encrypted by default

The current certificates and the audit reports behind them live in the trust center.

  • ISO 27001
    certified
  • GDPR
    compliant
  • Field-level
    permissions
  • Encrypted in transit
    and at rest

Security controls

Secure defaults,
for every account

Enterprise-level security built-in for everyone, not as a paid add-on.

  • Encryption in transit and at rest

    Every request runs over TLS, and everything we store is encrypted at rest. There's no cheaper tier where that changes.

  • Granular field-level permissions

    Salary, personal identifiers and health data are visible only to the roles you grant. The same rules hold in the web app, in the Slack agent, and over MCP.

  • An activity log behind every change

    Every change to an employee record is logged with who changed it, what changed, and when. That includes the changes agents make. You can export the log when an auditor asks.

  • No model training on your data

    We don't train AI models on customer data. It's processed to answer the request in front of it and nothing else. Which sub-processors touch it, and under what terms, is listed in the trust center.

  • Retention you set, deletion you can hold us to

    Retention runs per data category rather than one blanket rule, and on termination we delete or return customer data within 30 days under the DPA. You can export in full at any point, including on the way out.

  • Independently tested

    Our controls are audited against ISO 27001 by an external body, and the platform is penetration tested periodically by an outside party. Reports and current certificates are in the trust center.

Agent security

Safe and secure AI,
with human in the loop

Agents run workflows end-to-end. They also stop whenever human confirmation is needed.

Runs on its own

Reminders and chases, data hygiene and record updates, scheduling, reports and drafts, and review-cycle orchestration.

Always stops and asks

Pay changes, terminations, contract terms, legal commitments: anything you can't undo waits for a person.

Mistakes are visible and reversible

Full activity history and decision reasoning, always visible. Roll back changes with a single prompt, without extra manual work.

Two activity cards: a routine chase the agent completed on its own and logged, and a salary change it stopped before syncing to payroll, routed to a person to approve.

Documentation

The paperwork your legal team will ask for

Transparent and up-to-date security documentation available for you and other stakeholders.

  • Trust center

    Trust center

    Certificates, current controls and audit reports, kept up to date.

  • Data processing agreement

    Data processing agreement

    Our obligations as processor, and the terms our sub-processors are held to.

  • Privacy notice

    Privacy notice

    What we collect as a controller, and on what legal basis.

  • Sub-processor list

    Sub-processor list

    Who processes customer data on our behalf, and where.

  • Terms of service

    Terms of service

    The contract the rest of this sits under.

  • Document archive

    Document archive

    Earlier versions of the terms, privacy notice and DPA, kept on the record.

Frequently asked questions

Where is our data hosted?
In the EU. The trust center documents the specifics: regions, which sub-processor sits where, and what residency commitments are available. That's the version that stays current.
Do you train AI models on our data?
No. Customer data is used to answer the request at hand and for nothing else, never to train our models or a vendor's.
Who can see salary and personal identifiers?
Only the roles you grant. Field-level permissions follow the data into every surface that reads it, the Slack agent and MCP clients included, and every access is logged.
What happens if an agent gets something wrong?
It shows up in the activity log attributed to the agent, and anyone with permission to change that record can reverse it. Anything irreversible, from pay to exits to contract terms, never runs without a person confirming it first.
Are you ISO 27001 certified?
Yes, and GDPR compliant. Both ship in the base price, not a higher tier. The current certificate and the controls behind it are in the trust center.
Can we see a penetration test report?
The platform is penetration tested periodically by an external party. Reports are available through the trust center.
Can we export or delete our data?
Full export at any time, including on cancellation. On termination we delete or return customer data within 30 days under the DPA.