Legal

Security & data

Where your data lives, who can reach it, and what happens when you leave. Written for the person reviewing CompanyOS before their company buys it.

Version 2026-08-29 · Effective 29 August 2026

Who is who

Your company is the controller of the data it puts into CompanyOS — your employees’ records, your customers, your books. CompanyOS is the processor: we hold and process that data on your instructions and for no purpose of our own. That relationship is set out in the Data Processing Agreement, which you can read in full before you sign up, and which forms part of the contract when you do.

We do not sell data. We do not share it with advertisers. We do not mine one customer’s workspace to build anything for another.

Where it is kept

  • Data is stored in the European Union, in managed infrastructure operated by the sub-processors listed below.
  • Encrypted in transit with TLS, and encrypted at rest by the storage provider.
  • Backups are taken by the database provider on a rolling schedule and are subject to the same protections as live data.
  • Each customer is a separate tenant. Every query is bound to one company, and the application enforces that boundary on the server rather than in the browser.

Who can reach it

  • Inside your company, access follows the roles and admin types you set. Who may see salaries, contracts or payroll exports is your decision, and it is auditable.
  • On our side, access to production data is limited to the people who operate the service, used only to keep it running or to answer a support request you have raised.
  • Actions that matter — permission changes, exports, deletions — are written to an audit log you can read.

AI features

Some parts of CompanyOS can call an AI model — the AI Center, and assistants inside individual modules. This is the question buyers ask most often, so plainly:

  • Nothing is sent to an AI provider unless somebody in your company uses a feature that does it. AI is not running in the background over your data.
  • What is sent is the content that feature needs — the document being summarised, the message being drafted — and it is sent to the provider named in the sub-processor list.
  • Your content is not used to train models. We use providers’ business terms, under which submitted data is not used for training.
  • AI features can be left unused. If you would rather they were unavailable altogether, ask us and we will tell you exactly what that removes.

Sub-processors

The companies that process data on our behalf so the service can run. This is the same list that appears in the DPA; it is published here so it can be reviewed without reading the contract.

ProviderWhat it does
SupabaseDatabase, authentication, file storage, and edge functions
StripeSubscription billing and payment processing
SentryError monitoring and performance diagnostics
SMTP providerTransactional email (activation, portal links, notifications)
InngestBackground jobs and scheduled workflows
UpstashRate limiting and caching (when enabled)
AI providersOptional AI features when explicitly used by an authorised user

Getting your data out, and deleting it

  • A company admin can export the main datasets as CSV at any time, without asking us.
  • Deleting a company requires password confirmation and an acknowledgement that you have exported what you need. It then waits 30 days before anything is purged, and can be cancelled during that time.
  • After the waiting period, database rows, stored files, login accounts and billing records for that tenant are removed. Records under a legal hold are kept where the law requires it.

What we are still building

An honest list is more useful to you than a badge. CompanyOS does not hold an ISO 27001 or SOC 2 certification today. If your procurement process requires one, tell us before you buy rather than after — we would rather lose the deal than imply we have something we do not.

Asking us something

Security questionnaires, DPAs to counter-sign, and questions about any of the above: hemin.faraidun@gmail.com. Related reading: Privacy Policy, DPA, Terms, Cookies.

← Back to CompanyOS