Your data is yours. You own it, you can export it in bulk at any time, and you can delete it. We do not train public models on it.
Your data lives on Google Cloud Platform, in the US, with standard encryption in transit and at rest.
AI calls are routed to Google's Gemini models, chosen per job — writing, embeddings, image generation. Google is contracted for no-training commitments on your data.
One person runs this company today. That's the current constraint on how fast we can respond to an incident and how much compliance documentation exists.
We are not enterprise-ready in the formal sense. No SOC 2, no SSO on the base plan, no DPA as a default. All on the roadmap. Ask if you need specifics today.
Google Cloud Platform
Primary infrastructure — compute, storage, database, analytics (Cloud Run, Cloud SQL, Cloud Storage, BigQuery, Cloud DNS, Memorystore).
All customer data.
Firebase (Google)
Authentication and user session management.
Identity and session data.
Google AI / Vertex AI
AI generation (Gemini models), embeddings, image generation.
Prompts, completions, embedding text, image generation requests.
Resend
Transactional and marketing email delivery.
Recipient email addresses, email subject and body, delivery and engagement events.
Stripe
Billing and payments.
Payment method, billing contact, invoice data.
Pages, posts, emails, drafts, KB articles, CRM records, and the context you upload are yours. Export everything in bulk at any time. If you leave, you leave with your data.
Google, the provider we route to, is contracted under terms that prohibit training on customer data. We do not maintain our own foundation model or expose your content to another customer.
Your voice lives in retrievable context the AI pulls at generation time. It is not baked into shared weights.
Not to advertisers, not to data brokers, not to anyone. We retain operation logs scoped to your organization for audit and billing, and we do not mine them across customers. We sell the meter. That's it.
Your organization owns projects, and only members of your organization can see your content. Roles control what each member can do — read, write, admin, billing — with fine-grained permissions per app and per project. MCP API keys are scoped per organization: a key from one organization cannot reach another's data, and the AI itself cannot cross organizational boundaries.
Internally, engineers have access only to the systems they need, and production data access is logged. We do not read your content, inspect your drafts, or browse your CRM as routine. Jesse has administrative access to production by virtue of running the company; that access is used sparingly and logged. As the company grows, internal access tiers become formal. Today they are small because the company is small.
Encryption is TLS 1.2+ for every request, with public endpoints enforcing HTTPS, and GCP-managed AES-256 at rest for Cloud SQL, Cloud Storage, and BigQuery. Secrets live in Google Secret Manager and rotate on schedule. Data residency is the United States today; EU residency is a roadmap enterprise option and not available now. If you require EU residency today, we are not your tool yet.
Backups run daily across all Cloud SQL databases, with point-in-time recovery inside a 30-day window and per-project JSON and CSV exports on demand. When you delete a project, its content goes to a trash for 30 days, then is hard-deleted. When you delete an organization, all project data and customer records are wiped — hard deletion within 30 days of active systems, and removal from backup rotation within the backup window. There is no clause that retains your data past deletion.
Not yet. SOC 2 Type I, then Type II, is the first formal compliance program and the priority for the company through the next stretch. The audit process is to begin in the near term, with no date committed. ISO 27001 is planned after SOC 2 Type II.
Not on the base plan today. SSO and SAML are available on request as a flat-priced enterprise add-on, with self-service provisioning on the roadmap. Email plus password, Google, and Microsoft sign-in are supported, with two-factor authentication available.
Not today. Data lives in US GCP regions. EU residency with EU-only data pinning is a planned enterprise option, not shipped. Regional options beyond US and EU are not supported.
No HIPAA and no BAA — we do not support healthcare workloads. No FedRAMP and no government workloads. Payment data is handled entirely by Stripe; we do not touch card numbers directly, so our own PCI scope is minimal by design.
Error monitoring and alerting run on all services, with Jesse on call. A confirmed security incident affecting customer data means direct email to affected customers and a written post-mortem after resolution. There is no formal SLA today — the target is first response within one hour during business hours, and best-effort outside them. One-person on-call means slower response overnight. If you need tighter commitments today, we are not your tool yet.
Email security@giantcontext.com before posting publicly. We acknowledge receipt within two business days, investigate, and fix on a timeline proportional to severity. We'll credit you by name in the post-mortem if you want credit. There is no formal bug bounty program today, but we'll work out something fair case by case.
For a signed subprocessor list, a DPA, a contractual RTO or RPO, or anything a purchase decision hinges on, write to security@giantcontext.com. If we can't commit to it, we'll tell you that instead of inventing a date.