# Security · Communicate

> How Communicate protects your data: encryption at rest, TOTP two-factor on every account, per-Workspace isolation, self-serve export and delete, and a plain statement of the certifications we do not hold.

- **URL:** https://communicate.so/security

---

- [Home](/)
-
- Legal

# Security

Legal reference

Last updated: July 22, 2026

This page states exactly what Communicate protects today and, just as plainly, what we do not yet claim. No badge theater, no "bank-level encryption" hand-waving, no certification you cannot verify. Communicate is operated by TinyCheque, Inc. Questions can go to communicate@support.communicate.so.

On this page

- [Our approach](#our-approach)
- [Data encryption](#data-encryption)
- [Authentication and account access](#authentication-and-account-access)
- [Workspace isolation](#workspace-isolation)
- [How your data is used by the AI](#how-your-data-is-used-by-the-ai)
- [Data export and deletion](#data-export-and-deletion)
- [Payments and card data](#payments-and-card-data)
- [Privacy and GDPR readiness](#privacy-and-gdpr-readiness)
- [Subprocessors and hosting](#subprocessors-and-hosting)
- [What we do not hold](#what-we-do-not-hold)
- [Data retention after cancellation](#data-retention-after-cancellation)
- [Reporting a vulnerability](#reporting-a-vulnerability)
- [Contact](#contact)

## Our approach

We describe our security controls in terms of facts you can check, not adjectives. Every claim below is either true in production today or it is not on this page. Where we do not hold a certification or feature, we say so directly rather than implying it with "in progress" language we cannot substantiate.

You can verify most of what follows inside the product: export a Workspace, delete one, turn on two-factor authentication, and watch your Agent answer only from the knowledge you gave it.

## Data encryption

Data at rest in our storage layer is encrypted. This covers Conversations, Data Source content, Agent configuration, and Member records. A compromised storage volume or backup, on its own, does not hand an attacker plaintext customer data.

We describe this specifically as encryption at rest because that is the control we can verify and stand behind, rather than folding it into a broader claim that oversells what we have built. Data in transit is protected by standard transport-layer encryption (HTTPS/TLS).

## Authentication and account access

Every account, on every plan, supports TOTP-based two-factor authentication using a standard authenticator app. It is not an add-on tier or an enterprise-only toggle, and there is no SMS-only fallback pretending to be MFA. A leaked or guessed password alone does not get someone into a Member account with two-factor enabled.

- Keep your login credentials confidential and enable two-factor authentication on your account.
- Notify us at [communicate@support.communicate.so](mailto:communicate@support.communicate.so) if you suspect any unauthorized access to your account.
- You are responsible for the Members and end users you grant access to your Workspace.

## Workspace isolation

A Workspace is the tenant boundary in our data model, not a filter applied after the fact. It is the container everything else lives inside: Agents, Conversations, Data Sources, Credits, Members, and billing.

Queries and Agent retrieval are scoped to the Workspace that owns them. Data, Credits, and billing for one Workspace never leak into another. There is no shared pool and no cross-tenant path that could surface another customer's data in your Agent's answers.

## How your data is used by the AI

Your Agent answers from the knowledge base built out of your own Data Sources through retrieval. It is grounded in what you gave it, not an ungrounded completion. When retrieval does not surface a confident match, the Agent hands off to a human rather than fabricating a policy or price you never set.

We do not train shared or general-purpose AI models on your data. Inference runs on a third-party model (currently gpt-4o-mini accessed through OpenRouter) for inference only. Your Conversations and knowledge base stay scoped to your Workspace and are not used to train models that could surface your content to anyone else.

## Data export and deletion

You can export a Workspace's data or delete it entirely, on demand, from your account. Deletion is a full cascading delete that removes data across the systems that hold it, not a soft flag that leaves rows behind. Neither action requires a support ticket or a waiting period.

## Payments and card data

Dodo Payments is our merchant of record and holds the PCI (Payment Card Industry) boundary for payment processing. Your card details go directly to Dodo Payments, not through our servers or database. We store no card numbers, no CVVs, and nothing else in that category. PCI compliance for card handling is Dodo's boundary to hold, by design.

## Privacy and GDPR readiness

We say GDPR-ready, and we mean it precisely: the controls GDPR expects are in place, including encryption, self-serve export, self-serve deletion, data minimization by design, and no sale of your data. GDPR has no formal third-party certification to hold, so "compliant" would be an overclaim and "ready" is the accurate word.

We do not sell your data. Full detail on what we collect and how we handle personal data is in our Privacy Policy at /privacy. Where you act as a data controller and we process personal data on your behalf, a Data Processing Agreement (DPA) is available on request at [communicate@support.communicate.so](mailto:communicate@support.communicate.so).

## Subprocessors and hosting

We rely on a small set of third-party providers to run the Service. The named subprocessors are below; an up-to-date list is available on request.

ProviderPurpose

RailwayCloud hosting and infrastructure

OpenRouterAI model inference (currently gpt-4o-mini)

Dodo PaymentsPayment processing (merchant of record, PCI boundary)

## What we do not hold

So you can make a decision from this page alone, here is what we do not currently have. If any of these is a hard requirement for your organization, we are not the right fit yet, and we would rather you know today.

- No SOC 2, HIPAA, or ISO 27001 certification. If you process protected health information under HIPAA, we are not a suitable vendor.
- A single deployment region, with no multi-region failover or data-residency options.
- No SSO or SAML single sign-on yet.
- No independent third-party penetration-test report to share at this time.

We will not dress up a gap with a "certification in progress" line we cannot back with a date. When these change, this page changes.

## Data retention after cancellation

Cancellation stops your plan from renewing and preserves your paid access and Credits until the current billing period ends. It does not trigger an immediate data wipe. If you want your data removed sooner, you can trigger the export or full cascading delete yourself at any time, independent of your billing status. After account termination, we delete Customer Data within 30 days, except for records we are legally required to retain and backups deleted on our normal rotation.

## Reporting a vulnerability

If you believe you have found a security vulnerability in Communicate, please report it to us at [communicate@support.communicate.so](mailto:communicate@support.communicate.so). Include enough detail to reproduce the issue. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and address it. We appreciate responsible disclosure.

## Contact

For any question about security, privacy, or your data, contact us at [communicate@support.communicate.so](mailto:communicate@support.communicate.so). This is our single point of contact for all queries.

TinyCheque, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.
