Security

Your conversations stay yours.

Alex only works if you're willing to share the messy middle of your business. Here's how we earn that trust.

Data ownership

Your memory is yours

Every profile, conversation, and decision stored in Alex's memory belongs to you. Export or delete anytime. We never sell or repackage it.

No training

We don't train on your data

Your conversations with Alex are never used to train public foundation models. Ever. Full stop.

Encryption

Encrypted end-to-end in transit

All traffic is TLS 1.3. Stored data is encrypted at rest with AES-256. Keys rotated on a schedule.

Provider

Run on Claude (Anthropic)

Alex's reasoning happens on Claude models. Anthropic's Trust Center covers their data-handling posture.

Access

Least-privilege access

Engineers don't browse your data. Support can view what they need to resolve a specific ticket you raise, nothing more. Audited.

Compliance

SOC2 Type II in progress

Audit underway. GDPR / CCPA requests handled within statutory windows. DPA available on request for Team and Company plans.

Security FAQ

Direct answers.

Where is my data stored?
Primary region is US-East. Team and Company plans can request EU data residency.
Can I delete my account?
Yes, one click. Deletes every memory record, conversation, profile, and artifact within 30 days.
Who can see my conversations?
Only you. Team plans surface a shared business profile, not individual DMs. Company admins see usage metrics but not message contents.
What happens during outages?
We failover across model providers. Memory writes are replicated. Status page linked in the footer.

Questions we haven't answered?

Email security@getchiefofstaff.com. Engineers answer, not AI.