Company

Security

Last updated
What is actually built, described plainly. Where something is not in place yet, this page says so rather than leaving you to find out.

Access is scoped, not filtered

Every read of a board, canvas, file or meeting resolves the caller’s organization and department first, and queries are constrained to what that person can reach. The scoping is in the data access layer rather than in the interface, so a surface added later inherits it instead of having to remember it. Views that look across boards, like the Continuity Index and Contradiction Watch, only ever show boards you could already open.

An Executive sees across their organization’s departments. A member sees their own department, plus anything explicitly shared with them. Only a board’s owner can change it. Nothing leaves your organization unless someone in it publishes a board as a public link — which is deliberate, reversible, and shows a clean record rather than the workspace.

Joining an organization

People join through an invite link that works once and expires after seven days, and only when a seat is free. We store only a scrambled form of each link, so a copy of our database could not be turned into working invites.

Support cannot read your workspace

There is no back door for support to open a customer’s boards. Access requires consent you grant from your own account settings, lasts at most two hours once granted, and can be revoked at any time. Every request and every decision is written to our audit trail and to your organization’s own activity log. This is the control we would most want to see as a buyer, so it is the one we built first.

What the AI models see

Text you write on a board, files you upload and meeting transcripts are sent to Anthropic and OpenAI to pick out decisions, risks and questions and how they connect. They process it for us under their business terms, which do not allow training on it, and we do not train models on it either.

Every item picked out shows the exact words it came from, and a quote is kept only if it really appears in what was written, so the record cannot put words in anyone’s mouth. Anything the assistant suggests on its own is labelled as a suggestion, not presented as something a person said.

What you can check and take away

  • Activity log. Your organization’s owners and admins see who joined or left, invites, sharing, departments, branding, support access, settled conflicts and exports, and can download the whole log as a spreadsheet.
  • Your data. Anyone can download everything on the boards they own, as one file, from their Account page.
  • Your organization’s data. Owners and admins can download every board shared with the organization or filed in one of its departments, with its members and activity log.
  • Closing an account. When an owner closes the organization’s account, everyone has 30 days to download their data. After that it is permanently deleted, as the Privacy page describes.
  • Deleting your own account. Anyone can ask for their account to be deleted, with the same 30 days to download and change their mind.

Administrative surfaces

  • The internal admin area is gated by both a database role and an email allowlist. Either alone is not enough.
  • Administrative sessions can be required to carry a second factor (TOTP), enrolled per-account.
  • Administrative actions — including access granted under consent — are recorded.

Application hardening

  • State-changing requests carry CSRF protection.
  • Sensitive endpoints are rate limited, and endpoints that could otherwise confirm whether a private board exists return the same response whether it does or not.
  • Files are stored in a private bucket and reached through short-lived signed URLs, not public paths.
  • Payment details never reach our servers; checkout runs on Stripe.

Sub-processors

Vercel, Supabase, Anthropic, OpenAI and Stripe. Four of those handle the content you write: Vercel hosts the app, Supabase stores it, and the two model providers run the extraction that builds the Continuity Index. The Privacy page sets out exactly which and why. Data is held in the United States.

What we do not claim

We do not hold SOC 2, ISO 27001 or any other third-party attestation today, and we are not going to imply otherwise on a marketing page. We do not offer a contractual uptime guarantee on self-serve plans. We do not yet offer single sign-on (SAML) or SCIM provisioning, a choice of where data is stored, or a way to switch off the AI processing for one organization. If your procurement process needs any of these, talk to us before you start rather than after.

Reporting something

Found a vulnerability? Write to security@echo-logic.ai. Tell us what you found and how to reproduce it, give us reasonable time to fix it, and please do not access data that is not yours while proving the point. We will not pursue researchers who act in good faith.

EchoLogic
Continuity for how your team thinks, decides, and remembers why.
© 2026 EchoLogic. All rights reserved.