Austen
Security and data handling summary
Version 1.0 · [date]

Security and data handling

One page for the person in your organisation who has to sign this off. If you need a longer questionnaire answered, send it and we will answer it in full rather than send you a certificate we do not hold.

What we do with your content

WhatWhere it goesWhy
Your brief, plan, brand voice and article textCommercial AI model APIsTo research, write and score the article
The finished article and its briefProofed, over its APIHuman editing, returned as tracked changes
Your style guide, glossary and preferred spellingsStylus, in your own projectSo the engine and the editor work to the same rules
Audio or video you uploadA transcription model, then stored with your projectOnly what you choose to upload
Competitor pages we crawlFetched by our crawler at a rate limitPublic pages only. Nothing behind a login
Payment card detailsStripe onlyWe never see them. We hold a customer reference
Your email addressOur mail providerDelivery notifications and account email

What does not leave. We do not use your material for any other customer, as a training sample or in our marketing. We do not sell it, and we share it only with the subprocessors listed below. You can ask us to delete it at any time after delivery and we will do so within thirty days.

Subprocessors

SubprocessorPurposeWhat reaches it
AnthropicBy default: research, article generation, planning, scoring, briefs. Any text task can be routed to either model providerBrief, plan, brand voice, research notes, article text, and page text read for imports and competitor analysis
OpenAIBy default: images, transcription, embeddings, clean-up of transcripts and uploads, reading your website at setup. Any text task can be routed to either model providerImage prompts and your visual reference images, uploaded audio, transcripts and uploaded documents, your homepage text, page text for embedding, and the brief, brand voice and article text of any task routed to it
ProofedHuman editing, and optional sign-in with a Proofed accountThe article to be edited, its brief, the project name and the article title
StylusStyle guides and voice profilesAccount name and email, style rules, preferred spellings, voice samples
StripePayments and subscriptionsName, email, billing details, card data held by Stripe
MailgunTransactional emailEmail address, message content
GoogleOptional sign-in and Search Console performance dataOnly if you connect it
Cloudflare TurnstileBot protection on the sign-in formRequest metadata
SlackInternal notifications to our teamName, email, IP address and approximate location, device type, article titles on editing orders, account deletions
ip-api.comApproximate location of an IP address, for those notificationsIP address verify
Fathom AnalyticsCookieless visit analytics on our website and sign-in pagesPage visits and request metadata

How the application is secured

AuthenticationPasswordless. Sign-in is by an emailed link that works once and expires after fifteen minutes, or with a Google or Proofed account. There is no password login, so there is no password to leak. The sign-in request is rate limited and the form is bot-protected. Single sign-on through your own identity provider is not available.
AuthorisationPolicy-based authorisation on the core content models, with ownership checks elsewhere. Workspace membership governs access.
API accessOAuth 2, used by AI assistants over MCP, and personal access tokens, with idempotency keys on write operations. A personal token is either account-wide or limited to one project, read-only or read-write. On the REST API a project token cannot reach any other project. verify
URLsProjects, articles, briefs and other content records are addressed in URLs by UUID, never by an incrementing integer.
Outbound webhooksSigned HMAC-SHA256, so your systems can verify a request came from us.
Inbound integration endpointsCMS and style-guide callbacks are verified by HMAC signature, and a connected site with no secret is refused. Connecting a CMS uses a signed, single-use state. Stripe events are verified by Stripe's signature and Proofed status callbacks by a shared key.
Fetching your URLsEvery user-supplied URL, and every redirect it leads to, passes a server-side request forgery guard that refuses private and other non-public network addresses. A request carrying your CMS credentials never follows a redirect to another host.
Prompt injectionContent is sanitised and length-limited before it reaches a model, with clear delimiters between instructions and content.
PaymentsStripe webhook signatures are validated. Integration secrets are encrypted at rest. verify
StorageUploaded audio, video, documents and transcripts are held in private storage. Generated images, and the visual reference images you upload, are served from public addresses containing a random identifier, so that they can be embedded and published.
TransportHTTPS to the application and to every model, editing, style-guide, email and payment provider. verify

What we do not claim

We hold no security certification. We are not going to imply one on a questionnaire, and if that is a requirement for your organisation you should know it now rather than three weeks into a procurement process. What we will do is answer any questionnaire you send, in full, in writing, and tell you plainly where the answer is "not yet".

To be completed before issue

Fill these before this document is sent to anyone. Each is marked in the body with an orange badge.

Hosting[Country, region, provider and legal entity] verify
RetentionArticles, briefs and uploads are kept until you delete them or the account is deleted. Records of the requests made to the model providers for your work, which include the text sent and returned, are kept until the account is deleted. Activity logs are deleted after 90 days. [Backup copies] verify
DeletionOn request, within thirty days. An account can also be deleted from its settings: this permanently removes its projects, articles and briefs at once, and their stored files within a week. [Copies held by subprocessors and in backups] verify
Backups[Frequency, retention, restore testing] verify
Model provider terms[Each provider's current retention and training position, with the date checked] verify
Incident notification[Commitment and contact address] verify
Data processing agreement[Available / in preparation, and from whom] verify

Who to contact

Security and data questions: [email]. We aim to answer any questionnaire within five working days.

[Your company name] · company number [number] · [registered office] · derived from the application as built; confirm against production before issue