Security and privacy, stated plainly.
What we do to protect your workspace, what we keep and for how long, and where our compliance program actually stands — no certifications we don't hold.
How your data is protected
Isolation in the database
Every table that holds workspace data carries a workspace ID, and Postgres row-level security means a query only ever sees rows for the workspace making it.
Encrypted in transit
TLS on every connection to our apps and API. Customer-managed keys and single-tenant deployments are not offered today.
Role-based access
Every workspace has role-based permissions, and every write is checked against the caller's role in that workspace before it touches data.
Monitoring and incidents
Errors and alerts are monitored continuously. If an incident affects your data we tell you directly; we do not yet commit to a public response-time SLA.
Compliance status
We are not currently SOC 2, ISO 27001 or HIPAA certified. We honour GDPR data-subject rights for every user, wherever you are based — access, correction, erasure and portability — and respond within 30 days. GDPR is a regulation, not a certification, so we describe it as a commitment rather than an audit result. If a signed DPA, a security questionnaire or a specific framework is a requirement, email legal [at] amdital.com before you sign up.
How long we keep data
| Data | Retention |
|---|---|
| Workspace and account data | Deleted within 30 days of cancellation or a deletion request; backups are cleared within 90 days |
| Access and activity-monitoring logs | 90 days, deleted automatically |
| Ami conversation history and audit logs | 1 year, deleted automatically |
| Billing records | 7 years (required by tax law) |
| Data you export | Deleted 30 days after export |
Subprocessors
| Processor | Used for |
|---|---|
| Stripe | Billing |
| Maileroo | Transactional email |
| PostHog | Product analytics |
| New Relic | Error tracking and performance monitoring |
| OpenAI / Anthropic | AI responses for Ami, through the provider your workspace configures |
| Cloud hosting provider | Application, database and file storage hosting |
Integrations you turn on — such as GreytHR attendance sync — only move data because you enabled them, and only for that purpose. Live service health is on our status page. Full detail: security, privacy policy and terms of service.
Security questions buyers ask
Stop running your company on scattered tabs.
Get the AI-native operating system built to replace your stack — designed to get you running fast.