Security
How Curact protects customer content, in plain terms.
Last updated 2026-08-14
Access control
- Every table is protected by row-level security scoped to the workspace, so one customer cannot reach another's data.
- Roles inside a workspace decide who can edit, approve and administer.
- Contributor links are single-purpose tokens that expire and only expose the slides that person was asked to write.
Secrets and connections
- Slack and Trello tokens are encrypted with AES-256-GCM before they are stored, and are only decrypted on the server when a job runs.
- Tokens are never returned to the browser, and a workspace's connectors can be revoked at any time.
Staff access
- Curact staff can enter a customer workspace only for support, in read-only mode by default.
- Write access requires an explicit switch, is time-limited, and every entry and action is written to an audit log.
Data hygiene
- A privacy filter blocks personal identity numbers, card numbers, bank details, e-mail addresses, phone numbers and API keys from being indexed or sent to AI models.
- Each workspace decides how long indexed material, finished meetings, participant answers and logs are kept.
- Deleting a workspace removes its data, its connections and its stored files.
Reporting a vulnerability
Send findings to privacy@curact.ai. We acknowledge within two working days and will keep you updated until it is resolved. Please do not test against other customers' data.