Security and data protection
Last updated
Encryption
All connections to IGP one, from the website, the web app and our mobile apps, use HTTPS with TLS. Data is encrypted at rest in our database, file storage and backups.
Where data lives
Workspace data is stored in the European Union: our database on Supabase in Frankfurt, Germany, and files in Cloudflare R2 in the EU. Application servers run with Hetzner in Germany and Finland. Service logs, which contain no message content, are kept by Better Stack in the United States.
Isolation between businesses
Each business's data is kept separate. Row-level security in the database enforces that a workspace can only read and write its own records, in addition to checks in our application code.
Voice mode
In voice mode, audio travels over an encrypted connection to OpenAI for real-time processing. We don't store audio recordings; only the text transcript is saved in your chat history, protected like the rest of your workspace.
Access control
In the app, team members get role-based permissions set by the workspace owner.
Our internal tools and administration are protected by single sign-on and an access proxy, and staff access follows least privilege. Actions in admin tools are logged.
Audit logs
Sensitive actions in a workspace, such as publishing and connection or permission changes, and all actions in our admin tools, are recorded in audit logs.
Backups and recovery
We back up data daily with encryption, keep rolling backups for up to 35 days, and regularly test that backups can be restored.
Monitoring
We monitor errors and uptime continuously and are alerted to problems. Webhooks from payment and platform providers are verified by signature before we act on them.
Payments
Card payments are handled by Stripe. Card numbers go directly to Stripe and never touch our servers.
AI safety
Content from websites, documents and messages is treated as untrusted and can never change permissions or settings. Important actions require your approval.
Incident response
If a security incident affects your data, we will contain it, investigate, and notify affected customers and authorities as the law requires, including within 72 hours to EU authorities where GDPR applies. Business customers are notified within 48 hours of our becoming aware of a personal data breach, as set out in our Data Processing Agreement.
Reporting a vulnerability
If you believe you've found a security issue, email [email protected] with the details and steps to reproduce. Please give us reasonable time to fix it before sharing it publicly.
Test only against your own account. Never access, change or delete other customers' data, disrupt the Service, or use social engineering. If you act in good faith within these rules, we will not take legal action against you, and we will keep you informed as we fix the issue.
We don't currently run a paid bug bounty.
What we don't claim
We do not currently hold security certifications such as SOC 2 or ISO 27001. If that changes, we will say so here.
Social access tokens
Instagram access tokens are encrypted at field level in a vault, with keys kept outside the database. They are never shown in the browser, and we never ask you to paste a password or token.