Trust & Security

Your data security and privacy are our top priorities. Learn how we protect your information.

Encrypted at Rest

All data is encrypted using AES-256 encryption when stored.

Encrypted in Transit

TLS 1.3 encryption for all data transmitted to and from our servers.

Privacy First

We never sell your data. Your conversations remain private.

Data Isolation

User-Level Isolation

Each user's data is completely isolated. Your conversations, memories, and preferences are never accessible to other users.

Project-Level Isolation

Memory and context are scoped to individual projects. Work conversations don't mix with personal ones.

API Key Isolation

External API access is isolated per key. Each API key only accesses its owner's data and memory.

Memory Privacy

Full Transparency

View exactly what Aspendos remembers about you in Settings → Memory. See why each memory was stored.

User Control

Delete individual memories, clear all memory, or pause memory collection entirely at any time.

Data Export

Export all your memories as JSON for portability. Your data belongs to you.

No Training on Your Data

We do not use your conversations or memories to train AI models. Your data is used only to serve you.

Encryption

Data at Rest

  • • AES-256 encryption for all stored data
  • • Encrypted database backups
  • • Secure key management

Data in Transit

  • • TLS 1.3 for all connections
  • • HTTPS enforced everywhere
  • • Certificate pinning for mobile

API Security

  • • API keys hashed with bcrypt
  • • Rate limiting per key
  • • Audit logging for all access

Authentication

  • • Powered by Clerk (SOC 2 certified)
  • • Multi-factor authentication
  • • Session management

Compliance Roadmap

GDPR Compliance

Data export, deletion, and privacy controls implemented.

Active

SOC 2 Type II

Security controls and audit trail in preparation.

Q2 2025

HIPAA

Healthcare data compliance for enterprise customers.

Q3 2025

ISO 27001

Information security management certification.

Q4 2025

Infrastructure

Cloud Providers

Hosted on Vercel (SOC 2) and Google Cloud Platform (ISO 27001, SOC 2).

Database

Supabase (SOC 2 Type II) with automated backups and point-in-time recovery.

Authentication

Clerk (SOC 2 Type II) for secure user authentication and session management.

Questions?

For security inquiries or to report vulnerabilities, contact us at:

security@aspendos.net