Data Protection
Published 2026-07-04 · Living document
Infrastructure
The service runs on Cloudflare's global infrastructure. Data is encrypted in transit (TLS). Conversation state, knowledge stores and logs are held in Cloudflare storage services scoped per business.
Isolation
Each Digital Employee's knowledge lives in a namespace scoped to the business it serves. Cross-tenant access is denied by default in the platform's authorization layer. Our enterprise architecture additionally supports per-tenant envelope encryption with customer-managed keys and cryptographic shredding on deletion.
Auditability
Employee lifecycle events and governed actions are logged. Enterprise deployments support hash-chained, tamper-evident audit logs.
Regulatory orientation
We serve businesses in the United States, Brazil and Latin America, and we design our data practices with GDPR and Brazil's LGPD principles in mind: purpose limitation, data minimization, and honoring access, export and erasure requests. Formal compliance certifications are on our roadmap and will be documented in the Trust Center as they are achieved — we do not claim certifications we do not hold.
Incident response
Suspected security issues: [email protected] with subject "SECURITY". We commit to acknowledging security reports within two business days.