SECURITY & PRIVACY
The server stores. Your agent thinks, and holds every key. This page says exactly what is uploaded and what protects it — including the popular claim we refuse to make.
WHAT WE WON'T SAY
We will not tell you that, because for any transcript-syncing tool it is false. An agent transcript embeds tool results — every file the agent read, every diff it wrote, every .env it inspected — and those transcripts are uploaded: that is precisely what makes a wiped laptop recoverable. What makes it safe is what happens on the way. Secrets are redacted on your machine before upload, and every message is rescanned on arrival.
REDACTION, MEASURED
The redaction patterns are audited against a real developer machine's transcript history — not fixtures we wrote to pass. The audit reports kinds and counts only, never a matched value. Latest run:
651 messages — 0.5% — carried at least one secret: API keys, JWTs, connection strings, private keys. Redacting twice re-redacts nothing. And if a secret slips the client, the server's rescan quarantines the row before it is stored plainly and raises a team-wide attention item — every member's next standup says so, the owner included.
TENANT ISOLATION
Every product table carries row-level security that is enabled, forced, and backed by a real tenant predicate — and the proof is behavioural, not declared: the checks connect as the non-bypass application role, the one the app actually uses. A foreign tenant reads zero rows, cannot see the workspace exists, cannot insert into it, and a missing tenant context fails closed.
NOTHING TO STEAL
Your code is never used for inference on our servers, because there is no inference here: recall is Postgres full-text search, and the only model in the system is the one you already run, on your machine. Slack, Teams, Linear and Jira are reached through your own MCP connections, client-side. There is no server-side token vault, because there are no tokens to vault.
PRE-LAUNCH, PLAINLY
There is no SOC 2 report and no uptime history — the product is pre-launch, and we would rather say so than imply otherwise. There is no self-serve data purge yet either: the storage layer is delete-capable by design, and the purge path is planned, but nothing here will describe deletion as already happening until it does. Application data lives in managed Postgres and object storage under the platform's data-processing agreements — the live sub-processor inventory is at /ropa.