DecisionGraph is built on the principle of least privilege. Here's what that means in practice — and the technical details behind it.
Every page and API call travels over TLS (HTTPS). Your documents, decisions, and account data are encrypted at rest by our managed cloud database provider.
Your knowledge, decisions, history, and connected-system snapshots are scoped to your account. No other tenant can read them, and our own team cannot query around the isolation layer.
OAuth links to QuickBooks, Shopify, and Square ask for read-only permissions. You approve each scope before any data flows, and you can disconnect anytime.
Turn on email one-time codes for an extra sign-in step. Codes expire in 10 minutes, are limited to 5 attempts, and trusted devices can be remembered for up to 30 days.
We run on modern managed cloud infrastructure with automated patching, backups, and monitoring. We do not host our own data centers.
Delete a document, disconnect a system, or close your account and the associated data is removed. We do not use your data to train foundation models.
For IT leads, security reviewers, and anyone who wants the specifics.
We're happy to walk through our architecture, review access, or discuss a custom security assessment.
Formal SOC 2 Type II and ISO 27001 certifications are on the roadmap. Current controls are implemented as described above.