Data protection

Your knowledge stays yours.

Corpussage indexes your content to answer questions. It does not store, train on, or share your data. Everything is encrypted in transit and at rest, with permission boundaries that mirror your existing access controls.

Built for teams that handle sensitive information

Security is not an add-on. These controls ship in every plan.

Encryption at rest and in transit

All indexed content is encrypted at rest using AES-256. Data in transit is protected by TLS 1.3. Encryption keys are rotated automatically on a rolling schedule.

Permission-aware indexing

Corpussage respects your existing source permissions. If a user cannot see a document in Confluence, they cannot surface it through Corpussage answers either. Access boundaries are enforced at query time.

SOC 2 controls in design

We are a bootstrapped team building toward SOC 2 Type II. Our infrastructure and access controls are designed to the SOC 2 framework. We share our trust documentation with teams evaluating enterprise plans.

No training on your data

Your team's documents and answers are never used to train AI models, including our own. Your knowledge base remains private to your organization. This is a hard architectural commitment, not a setting.

Audit logs

Every answer, source lookup, and admin action is logged. Teams and Growth plan customers can export query logs for compliance review. Enterprise customers get log streaming to their own SIEM.

Data residency options

All data is hosted on AWS in the US-East region by default. Teams on the Teams plan can request EU data residency for GDPR compliance. Residency selection is set at workspace creation.

Privacy compliance

We are transparent about what we support and what we are working toward. No false certifications.

GDPR

Corpussage supports GDPR compliance for EU-based teams. You can request data deletion for any workspace. User data is not shared with third parties for marketing. Data processing agreements are available on request.

CCPA

California users have the right to know what data is collected and to request deletion. We collect only the data needed to answer your questions: indexed content, query logs, and account information. No data is sold.

What we index

We index document content, titles, metadata, and access permissions from your connected sources. We do not read email, calendar, or any source you have not explicitly connected. You can disconnect any source and delete its index at any time.

Subprocessors

Our current subprocessors for AI inference and hosting are AWS and Anthropic. We maintain a current subprocessor list and notify customers of changes 30 days in advance. GDPR data processing agreements are in place with all subprocessors.

Questions about our security posture?

We share our trust documentation with teams on Teams or enterprise plans.