How we protect your data
- OAuth first — we never see or store your password when possible.
- Minimal access — we request the narrowest scopes needed (read + modify labels for Gmail, etc.).
- Ephemeral processing — most classification happens in seconds and content is not retained.
- Encryption in transit and at rest — TLS 1.3 everywhere, AES-256 for any stored metadata.
- On-device option — coming soon for macOS/Windows (models run locally, only syncs your learned preferences).
Compliance
SOC 2 Type II in progress. GDPR & CCPA compliant by design. Data Processing Addendum available for enterprise customers.
Bug bounty & responsible disclosure
We run a private bug bounty program. Report security issues to security@irishgoodbai.ormus.solutions. We typically respond within 24 hours.
High-fidelity mock. In a real product this page would link to the actual SOC 2 report, DPA, and status page.