Skip to content

Security

Controls you can inspect.

See how we isolate each tenant, what data goes to which subprocessor, and how approval gates keep agents from acting alone.

Tenant model

Customer workspaces stay isolated. Access is denied by default.

Tenant isolation

Customer workspaces are logically isolated. Covered portfolio data is scoped to the authenticated organization, and privileged access paths require an explicit authorization decision before they run.

Authorization

Every sensitive operation authenticates the caller and enforces role and organization boundaries before data is returned or changed. Access is denied by default outside those checks.

Encryption

Data is encrypted in transit (TLS) and at rest via our infrastructure providers. Customer-supplied LLM credentials are encrypted at rest when BYOK is configured.

Hosting and region

Application and data processing currently run in the United States. EU data residency is not a product option today — we state that plainly in diligence rather than implying otherwise.

LLM data handling

What leaves the tenant, and whether it trains a model.

Bring-your-own-key is supported for commercial providers. Bring-your-own open-weight model is supported on customer-controlled neoclouds. In both cases, the endpoint you configure — and its contract — governs the call.

Anthropic

Data that may leave the tenant
Prompts, tool context, and model outputs for configured agent workflows.
Used for model training?
No. Under Anthropic commercial API terms, API inputs are not used to train foundation models by default.

Google

Data that may leave the tenant
Prompts and outputs when a Google / Gemini model is the configured provider.
Used for model training?
No. Under Google Cloud / Gemini API commercial terms applicable to paid API use, customer prompts are not used to train Google foundation models by default.

OpenAI

Data that may leave the tenant
Prompts and outputs only when an OpenAI model is explicitly configured.
Used for model training?
No. Under OpenAI API data-usage defaults for paid API customers, API inputs are not used to train models by default.

Open-weight models (customer neocloud)

Data that may leave the tenant
Prompts, tool context, and outputs are sent only to the inference endpoint you designate. MigrateForce does not retain a parallel copy for model training.
Used for model training?
No by MigrateForce. Weights, logs, and retention stay under your neocloud / self-hosted contract — you control whether any telemetry is retained or used to fine-tune.

MigrateForce does not train foundation models on customer content. Customer content is not used to improve a MigrateForce-owned model. Provider defaults above reflect commercial API terms as of publication; enterprise contracts can tighten further.

Compliance status

SOC 2

Planned

ISO 27001

Planned

We honor applicable data-subject rights and publish a Data Processing Agreement. That is not the same as a completed SOC 2 or ISO certification.

Subprocessors

SubprocessorRoleRegion
Supabase Inc.Database hosting and authenticationUnited States
Google LLCCloud infrastructure and optional AI servicesUnited States
Resend Inc.Transactional emailUnited States
Anthropic PBCAI model processing for configured agentsUnited States
OpenAI, L.L.C.Optional AI model processing when configuredUnited States
Stripe, Inc.Payment processing when paid services are usedUnited States

Changes follow the notice process in the DPA. Full legal terms: Privacy Policy.

Retention, deletion, incidents

What we keep, what you can delete, who to call.

Retention

Account and engagement data is retained while needed to operate the service and meet legal obligations. Enterprise retention can be scoped in the executed agreement.

Deletion

Request deletion via privacy@sociallabs.com (Social Protocol Labs operates MigrateForce). We honor applicable legal rights subject to retention requirements.

Incidents

Confirmed breaches affecting your personal data are notified without undue delay per the DPA. Contact privacy@sociallabs.com.

Next step

Run an assessment on your own context, or book a security walkthrough for enterprise diligence.