Security & Privacy

    Built to be trusted with your work.

    Pocodot reads your messages, runs your tasks, and holds the keys to your tools. That's a lot of trust. Here's exactly what we do to deserve it.

    Compliance posture

    • SOC 2 Type IIAudit in progress
    • GDPRAligned
    • CCPAAligned
    • HIPAAEnterprise
    • ISO 27001Roadmap
    • DPAAligned

    Six promises.

    Each one is something we do today, or something we're rolling out within weeks. Where we're not all the way there yet, we say so.

    The four questions you're really asking.

    Plain answers, no hedging.

    "Can another customer see my data?"

    No. Every piece of data we store is tagged with your workspace. Every part of our system checks that tag before answering any question. We have automated tests that try to break this rule - they have to pass before any code change ships. We're adding a second layer of protection at the database level so even a future bug can't leak your data.

    "Will you train AI on what I say?"

    No. The AI providers we use (Anthropic, OpenAI, Google) are contractually forbidden from training on your data. Our integration partner (Composio) may use anonymized usage statistics - never your message content. The full breakdown is on our Sub-processor page.

    "What if you get hacked?"

    Then we tell you within 72 hours. We'll explain what happened, what was affected, and what to do. We follow GDPR Article 33 to the letter. Our incident plan covers detection, containment, customer notice, and a public post-mortem afterward - so the same mistake can't happen twice.

    "What happens when I leave?"

    You get an email confirming your data has been destroyed. The email includes a deletion certificate signed with our public signing key - which means you can independently verify it wasn't faked. The key fingerprint is published at /security/deletion-key.

    Who can sign in, and how.

    Plain access controls. You're always in charge of who has the keys.

    • Sign in with email and password

      Your password is never stored as text.

    • Sign in with Google

      One click, no password to remember.

    • Sign in with a magic link

      We email you a one-time link.

    • Two-factor authenticationRolling out

      An extra code from your phone, every time you sign in.

    • Single sign-on (SSO)Rolling out

      For teams using Okta, Microsoft, Google Workspace, or OneLogin.

    • See who else is signed in

      Anytime, in your settings. Sign anyone out with one click.

    What we use, and why.

    The companies that help us run Pocodot. We give 30 days' notice before adding any new one.

    Anthropic, OpenAI, Google Gemini
    These are the AI brains. Your messages pass through them so we can reply. None of them train on your data.
    Composio
    Connects Pocodot to your tools (Slack, Notion, Calendar). They never see message content.
    DigitalOcean
    The servers Pocodot runs on (Singapore region).
    Stripe
    Handles payments. Your card details never touch our system.
    Resend
    Sends our emails to you.

    Where you stand.

    No spin. Just where we are.

    • Uptime target: 99.9% (and rising).

      Live status is published.

    • Backups: every night, encrypted, kept for 30 days.
    • Independent security audit: in progress.Audit in progress

      We're working with a top-tier auditor toward SOC 2 Type II - the gold standard for SaaS security. The audit window opens this summer; the report follows.

    • Privacy law: GDPR-compliant. We sign DPAs in minutes.

      Email privacy@pocodot.ai or grab the template from our trust portal.

    • HIPAA: coming with our Enterprise plan.

      Talk to us if you need it sooner.

    Common questions.

    Twenty answers in plain English. Each one is yes-or-no first, then the why.

    The basics

    Where is my data stored?

    On secure servers in Singapore today. Enterprise customers can choose the United States, Europe, or Asia-Pacific.

    Who can see my conversations?

    Pocodot's AI processes your messages so it can reply - that's its job. No human at Pocodot reads your messages as part of normal work. A small group of named on-call engineers can look at logs during a support investigation, and that access is itself logged.

    Will you sell my data?

    No. Never. It's written into our privacy policy and our customer contracts.

    Will you train AI on what I say?

    No. Our AI providers (Anthropic, OpenAI, Google) are contractually forbidden from training on your data. Our integrations partner (Composio) only sees anonymized usage patterns - never message content.

    Encryption and your data

    Is my data encrypted?

    Yes. Everything you save with us is scrambled - both when it's traveling over the internet and when it's sitting in our database. Only Pocodot's running system can unscramble it, and only when you ask it to.

    Does each customer have a separate key?

    Yes. Every workspace gets its own encryption key. One customer's key cannot open another customer's data - even by mistake.

    What about end-to-end encryption?

    We're not end-to-end encrypted, and we won't pretend to be. Pocodot is an AI assistant - it has to read and act on your messages to do its job. We protect your data at every other step (in transit, at rest, in our backups), but our system does see the message content while it's working.

    Can I get a copy of all my data?

    Yes. Click "Download my data" in your settings. You'll get a single zip file with everything Pocodot knows about you.

    Can I delete my data?

    Yes. Click "Delete my workspace" in your settings. We destroy the key that unlocks your data. You'll get a signed certificate by email confirming it.

    Can I really verify the deletion certificate?

    Yes. The email contains the certificate, the data inside it, and the steps to verify it with one open-source command. Our public signing key is published at /security/deletion-key - so you don't have to take our word for any of it.

    Sharing your workspace

    How do I keep teammates' access in check?

    You see every active sign-in in your settings - device, location, last active. One click signs anyone out. When teammates leave, removing them from your workspace removes all their access immediately.

    Can I require two-factor authentication for my team?

    Yes - rolling out shortly. You'll be able to require an extra one-time code (from an authenticator app or a security key) for every sign-in.

    Do you support SSO with Okta, Microsoft, Google Workspace?

    Yes - rolling out for Enterprise customers. Single sign-on with SAML 2.0 and automatic user provisioning (SCIM).

    Trust and compliance

    Are you SOC 2 certified?

    Not yet - and we won't pretend otherwise. We're in the audit process now with a top-tier auditor. The report is expected within the next few quarters. We'll publish it the moment we have it.

    Do you comply with GDPR?

    Yes. We can sign a Data Processing Agreement with you in minutes. Email privacy@pocodot.ai or grab the template from our trust portal.

    Do you have a HIPAA Business Associate Agreement?

    HIPAA is coming with our Enterprise plan. Healthcare prospects: talk to us so we can sequence your timeline.

    Where can I read your full security details?

    Two places. Our security architecture page is the long technical version of everything here. Our trust portal hosts our compliance documents behind a one-click NDA.

    What if something goes wrong

    What if you get hacked?

    We tell affected customers within 72 hours, in line with GDPR Article 33. We explain what happened, what was affected, and what to do. We publish a public post-mortem on our blog within 30 days unless legal counsel says otherwise.

    What if you go out of business?

    Your data isn't held hostage. You can export everything at any time. If we ever shut down, we'll give you 90 days' notice and the tools to take your data with you.

    How do I report a security problem?

    Email security@pocodot.ai. Include what you found and how to reproduce it. We credit responsible reporters in our release notes (with their permission). Our PGP key is on our deletion-key page.

    What Pocodot sees in your Slack.

    Every connection uses Slack's official login. Tap any item to see why we ask, and how to revoke it in one click.

    • See your public channelschannels:read

      Why we need it: So Cole can find the right channel when you ask 'post this to #marketing'.

      How to revoke: Slack → Apps → Pocodot → Configuration → Remove App.

    • Join public channelschannels:join

      Why we need it: So Cole can automatically join public channels and learn your team's context without manual invites.

      How to revoke: Slack → Apps → Pocodot → Configuration → Remove App.

    • Post messages on your behalfchat:write

      Why we need it: So Cole can reply, post summaries, and send the messages you ask for.

      How to revoke: Slack → Apps → Pocodot → Configuration → Remove App.

    • Read direct messages with Coleim:history

      Why we need it: So Cole can carry on a conversation with you, not start fresh on every message.

      How to revoke: Slack → Apps → Pocodot → Configuration → Remove App.

    • See who is on your teamusers:read

      Why we need it: So Cole can route 'send this to Sara' to the right teammate.

      How to revoke: Slack → Apps → Pocodot → Configuration → Remove App.

    • Read files you share with Colefiles:read

      Why we need it: So Cole can summarise the deck or PDF you just dropped in the chat.

      How to revoke: Slack → Apps → Pocodot → Configuration → Remove App.

    Have a security review to run?

    We've answered most questions on this page. For the rest, talk to us. Most replies within one business day.

    Ready to hire your first AI agent?

    Join thousands of teams using AI agents to automate work.

    Get Started Free