SECURITY AND TRUST

Built to be trusted with your customers' words

An AI agent reads your documentation and talks to your customers. That deserves more than a badge wall. Here is exactly how we handle your data, in plain language.

Your content trains your agent only

Documents, conversations and articles ground your workspace AI and nothing else. We never use your data to train models for other customers or for foundation model providers.

Grounded answers with an audit trail

Every AI reply records which sources it used and its confidence. Below threshold it declines and logs the gap. You can inspect any answer after the fact.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Secrets in a managed vault, access controlled and logged.

Export and delete, any time

Full export of leads, conversations, tickets and articles. Deletion requests are honored across primary storage and backups on a fixed schedule.

Access control that scales

Role-based permissions on every plan. SSO and SAML, plus a full audit log of every admin action, on Scale.

Human takeover is a control, not a feature

Your team can step into any AI conversation instantly. Boundaries you set, allowed and forbidden topics, are enforced on every reply.

THE DETAILS

Compliance and data handling

Plain answers to the questions a security review will ask.

Where does my data live?

Primary infrastructure runs in US data centers with encrypted backups. EU data residency is on the roadmap; if that is a requirement for you, talk to us and we will be straight about timelines.

Is Cadey SOC 2 certified?

SOC 2 Type II is in progress. We run the controls today, continuous monitoring, access reviews, and vendor management, and will publish the report the day we have it. Ask sales for the current security packet and subprocessor list.

Do you sign DPAs? GDPR?

Yes. A standard DPA is available on every paid plan, and we operate as a processor under GDPR for your customer data, with documented subprocessors.

Which AI models do you use, and do they see my data?

We use commercial foundation models under agreements that prohibit training on your data, with zero retention options enabled where the provider offers them. Scale plans can pin or restrict which models are used.

What happens to my data if I leave?

Trial and cancelled workspaces keep data intact for 90 days for export, then it is deleted. You can request earlier deletion at any time.

FOR YOUR REVIEW

Want the security packet?

Architecture overview, subprocessor list and our current controls, ready for your security review.