Security

How Curact protects customer content, in plain terms.

Last updated 2026-08-14

Access control

  • Every table is protected by row-level security scoped to the workspace, so one customer cannot reach another's data.
  • Roles inside a workspace decide who can edit, approve and administer.
  • Contributor links are single-purpose tokens that expire and only expose the slides that person was asked to write.

Secrets and connections

  • Slack and Trello tokens are encrypted with AES-256-GCM before they are stored, and are only decrypted on the server when a job runs.
  • Tokens are never returned to the browser, and a workspace's connectors can be revoked at any time.

Staff access

  • Curact staff can enter a customer workspace only for support, in read-only mode by default.
  • Write access requires an explicit switch, is time-limited, and every entry and action is written to an audit log.

Data hygiene

  • A privacy filter blocks personal identity numbers, card numbers, bank details, e-mail addresses, phone numbers and API keys from being indexed or sent to AI models.
  • Each workspace decides how long indexed material, finished meetings, participant answers and logs are kept.
  • Deleting a workspace removes its data, its connections and its stored files.

Reporting a vulnerability

Send findings to privacy@curact.ai. We acknowledge within two working days and will keep you updated until it is resolved. Please do not test against other customers' data.