Trust

Security

Last updated: September 13, 2026

How we protect your data

  • Encryption in transit. Traffic to and from the platform is encrypted over TLS.
  • Access controls. Data is protected by row-level security rules so that accounts can reach only their own records, and administrative access is limited to the people who need it.
  • Managed infrastructure. We build on established providers (see our sub-processors) rather than operating our own data centres.
  • Secrets management. Credentials and API keys are held in a managed secrets store and injected at runtime, not committed to source code.
  • Least data. We store the personal information described in our Privacy Notice and no more, and we retain it only as long as we need it.

No system is perfectly secure, and we are continuously improving. This page describes our current practices, not a warranty.

Reporting a security issue

If you believe you have found a security vulnerability, please tell us before disclosing it publicly. Email security@squidgy.ai with enough detail for us to reproduce the issue. We will acknowledge your report, keep you updated, and work in good faith to fix confirmed issues promptly.

Please do not access, modify, or delete data that is not yours, degrade the service for others, or run automated scanning that could disrupt the platform. We do not currently operate a paid bug-bounty programme, but we are grateful for responsible disclosure and will credit reporters who wish to be named.

Data protection

For how we handle personal information, your rights, and our sub-processors, see our Privacy Notice. Business customers who need a data processing agreement can request one at privacy@squidgy.ai.

Chat with Squidgy