Trust Center

Updated
GDPR
CCPA / CPRA
SOC 2 Type 2Readiness in progress

Review our security controls, service providers, policies, and technical documentation. For supporting evidence or a security questionnaire, contact our security team.

Controls

Evidence methods and dates apply to the scope described in each row. “Verified” refers to the dated internal check shown. “Adopted” identifies an established policy or procedure. “Reviewed” describes a document review; local tests are labelled separately.

Infrastructure

Infrastructure controls and verification dates
ControlEvidence
Core hosting

Application and database AKS clusters, customer Blob storage, and PostgreSQL backup storage are hosted in Azure Central US. AI processing has a separate service scope.

SOC 2 Type 2
VerifiedConfiguration checked

Data protection

Data protection controls and verification dates
ControlEvidence
Object and backup encryption

Customer files and PostgreSQL backups in the inspected Azure Blob accounts use Microsoft-managed encryption at rest.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedConfiguration checked
Database disk encryption

The inspected database-cluster managed disks use platform-managed encryption keys.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedConfiguration checked
Storage transport and public access

Customer and backup Blob accounts require HTTPS with TLS 1.2 or newer and have public Blob access disabled. This control applies to these storage accounts.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedConfiguration checked
Retention and erasure requirements

Our procedure requires deletion scope to account for application records, artifacts, model-service data, logs and backups, including reapplication after restoration. Completion periods depend on the agreed scope and verified workflow.

GDPRCCPA / CPRA
AdoptedProcedure adopted
Browser privacy signals

Website analytics suppression for Global Privacy Control and Do Not Track has passed local tests. Deployment verification is pending; this evidence applies to the tested website change.

CCPA / CPRA
Tested locallyLocal implementation tests

Access control

Access control controls and verification dates
ControlEvidence
Workspace and project authorization

Server-side checks govern workspace administration and project access. Project permissions can be assigned to users or workspace groups.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedImplementation reviewed
Evaluation artifact access

File, preview, and thumbnail access is checked against the authenticated workspace, project permissions, and deletion status. An artifact address alone does not grant access.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedImplementation reviewed
Workspace credentials

Workspace credentials use AES-GCM envelope encryption. Management responses expose metadata and masked hints; runtime resolution checks execution context, expiry, and active grants.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedImplementation reviewed
Key Vault protections

Production Azure Key Vault has role-based access control, purge protection, and 30-day soft deletion enabled.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedConfiguration checked
Workload identity

Workload identity is enabled on the application AKS cluster. This configuration is separate from human administrator access controls.

SOC 2 Type 2
VerifiedConfiguration checked

Recovery and operations

Recovery and operations controls and verification dates
ControlEvidence
Storage recovery protections

Customer and backup Blob accounts have versioning and 30-day soft deletion enabled. Recovery protection periods are distinct from customer erasure timelines.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedConfiguration checked
Database restoration tested

A backup was restored into an isolated test cluster. The documented exercise checked schemas, representative row counts, and read/write behavior.

GDPRCCPA / CPRASOC 2 Type 2
VerifiedRestore documented
Credential-access events

The workspace secret service records runtime access and denied-access events with execution context. Recognized signed storage URLs are sanitized in application logging.

SOC 2 Type 2
VerifiedImplementation reviewed
Operational log retention

The production Azure Log Analytics workspace is configured with 30-day retention.

SOC 2 Type 2
VerifiedConfiguration checked

Governance and policies

Governance and policies controls and verification dates
ControlEvidence
Security governance

IS-01 establishes accountable ownership, policy maintenance, evidence reviews, and tracking of implementation gaps and exceptions.

GDPRCCPA / CPRASOC 2 Type 2
AdoptedPolicy adopted
Access lifecycle and personnel

IS-02 requires individual accounts, least privilege, privileged-access approval, quarterly access reviews, departure access removal, and confidentiality obligations.

GDPRCCPA / CPRASOC 2 Type 2
AdoptedPolicy adopted
Information handling and deletion

IS-03 defines restricted information and requirements for retention inventories, authorized deletion requests, downstream reconciliation, and backup treatment.

GDPRCCPA / CPRASOC 2 Type 2
AdoptedPolicy adopted
Supplier and AI processing reviews

IS-04 requires a provider inventory, approval before new processing, review of data scope and retention terms, and annual supplier reviews.

GDPRCCPA / CPRASOC 2 Type 2
AdoptedPolicy adopted
Secure development and infrastructure

IS-05 defines security review and validation of changes, credential handling, vulnerability triage, and infrastructure protection requirements.

SOC 2 Type 2
AdoptedPolicy adopted
Incident response

IS-06 defines reporting, incident ownership, containment, evidence preservation, recovery, communications, and exercise requirements.

GDPRCCPA / CPRASOC 2 Type 2
AdoptedPolicy adopted
Backup and continuity responsibilities

IS-07 requires backup review, documented recovery procedures, isolated restore exercises, and measurement of recovery objectives.

GDPRCCPA / CPRASOC 2 Type 2
AdoptedPolicy adopted
SOC 2 readiness program

Our Security readiness program defines the system scope, maps controls to the Common Criteria, and maintains a risk assessment, evidence register, and operating review procedures.

SOC 2 Type 2
ReviewedProgram documented
Privacy-request handling

Our procedure covers identity and authority checks, access, correction and deletion requests, customer-controller routing, deadlines, and evidence of completion. Requests can be sent to [email protected].

GDPRCCPA / CPRA
AdoptedProcedure adopted
Processing and supplier inventory

An internal register documents core hosting, identity, AI processing, operational records and recovery storage, with data scope, retention questions and follow-up reviews for optional integrations.

GDPRCCPA / CPRA
ReviewedRegister reviewed

Subprocessors

Core service providers and their processing roles. Request the complete processor scope for your intended workflows, including optional integrations.

Core service providers and processing scope
ProviderPurposeData involvedProcessing location
Microsoft AzureApplication hosting, databases, storage, backups, and AI processingCustomer content and application data; prompts and responses for AI workflows.Core infrastructure: Central US. AI resources: Central US and East US; Global deployments may process across supported geographies.
Auth0 (Okta)User authentication and identity managementAccount and identity information used for authentication.US tenant hosting.
CloudflareDNS, proxying, and traffic delivery for websites and customer application/API trafficRequests, responses, and associated network metadata for proxied traffic, including streaming connections.Global network. Core Azure hosting location does not restrict all edge processing.

Teammately operates supporting services within its Azure infrastructure, including PostgreSQL managed with CloudNativePG and self-hosted Umami analytics. These software projects are not separate service providers receiving customer data.

Resources

Technical summaries and policy information for your review. Each summary describes its own scope.

Technical documentation

Architecture and customer data flowsCore hosting, identity, application traffic, and AI boundariesRead summary

Customer application and API requests, including streaming responses, pass through Cloudflare to Teammately’s Azure application infrastructure. Auth0 provides identity authentication. The authenticated API boundary performs workspace and project authorization before routing work to internal services.

Application services and PostgreSQL run on Azure Kubernetes Service. Customer objects and database backups are stored in Azure Blob Storage. Core hosting is in Central US. AI processing and traffic delivery have separate geographic scopes.

Durable evaluation workflows are handled by backend workers. Depending on the workflow, customer content is included in prompts or files sent to model services. Customer-configured integrations should be reviewed as part of the deployment’s processing scope.

Scope: core service architecture. Source and configuration review, September 2026.

AI processing and customer data useTraining commitment, model processing, and response storageRead summary

Teammately does not use customer workspace data to train shared generative models without express written agreement. Processing customer content to perform a requested evaluation is separate from training a shared model.

The reviewed primary evaluation client requires an Azure OpenAI or Microsoft Foundry endpoint. Azure Global deployments may process prompts and responses across supported geographies. Some evaluation workflows request stored responses; retention must be assessed for the specific feature and workflow.

Microsoft’s AI data processing documentation describes service storage, model training terms, and abuse monitoring. Contact us to review the requirements for your selected workflows.

Scope: reviewed primary evaluation client and Azure model processing. Reviewed September 14, 2026.

Access control and credential handlingWorkspace permissions, artifact authorization, and secretsRead summary

Application permissions are scoped to workspaces and projects. Artifact access checks include the authenticated workspace, project access, and deletion status. Possession of an artifact URL does not itself grant access.

Workspace credentials use envelope encryption and are managed separately from evaluation scripts. Management responses return metadata and masked hints. Runtime resolution checks execution context, expiration, and active grants. Azure Key Vault provides infrastructure secret access and recovery controls.

Internal policy requires an authorized business purpose for personnel access to customer content and records of access decisions. Product authorization and human infrastructure administration are distinct controls.

Implementation reviewed September 11; Key Vault configuration checked September 13; policy adopted September 14, 2026.

Backup and recoveryStorage protections and the documented restore exerciseRead summary

A PostgreSQL backup was restored into a separate test cluster. The recorded validation covered schema inventory, representative row counts, and read/write testing.

Customer and backup Blob accounts have versioning and 30-day soft deletion enabled. These protections help recovery; they do not define a guaranteed recovery objective or maximum data-erasure period.

Our internal policy establishes backup review and restore-test responsibilities. Discuss recovery objectives and deletion requirements with us for your deployment.

Historical exercise: July 4, 2026. Storage configuration checked September 13, 2026.

Internal policies

Teammately maintains internal policies governing the following areas. Adopted , they define responsibilities, review requirements, and how implementation gaps are tracked.

  • IS-01 · Governance and responsibilities
  • IS-02 · Access control and personnel security
  • IS-03 · Information handling, retention and deletion
  • IS-04 · Supplier and AI processing
  • IS-05 · Secure development and infrastructure
  • IS-06 · Incident response
  • IS-07 · Backup and business continuity
Request policy documentation ↗
Privacy requests and retentionRequest handling, customer instructions and erasure scopeRead summary

Our adopted procedure covers identity and authority verification, request ownership, response deadlines, customer-controller coordination and completion evidence. Contact [email protected] for access, correction, deletion or other privacy questions.

Retention and erasure reviews account for application records, files, model-service data, operational records and backups. Backup recovery periods are separate from permanent erasure timelines. Processing locations and optional integrations are reviewed for the intended customer workflow.

Procedure adopted September 14, 2026. Request supporting documentation through our privacy contact.

Legal documents

Frequently asked questions

How can I make a privacy request?

Email [email protected] to request access, correction or deletion, or ask a privacy question. These messages reach our accountable owner. We verify identity and authority as appropriate. For customer-controlled workspace data, we coordinate with the customer organization and act on its documented instructions.

Who is responsible for processing personal information?

Teammately Inc. is the contracting company. We process customer workspace content on the customer’s instructions. Our Privacy Policy describes our own processing for website, account and business administration. The applicable agreement and purpose determine the processing role.

What do the framework marks show?

The GDPR and CCPA / CPRA marks identify the privacy frameworks addressed by this page. The SOC 2 mark identifies our Security readiness program targeting a Type 2 examination, with readiness in progress. Individual controls describe their evidence, status and review date.

Is customer data used to train shared AI models?

Teammately does not use customer workspace data to train shared generative models without the customer’s express written agreement. Models used in workflows process data to provide the requested service. Provider processing and retention terms apply separately.

Where is customer data hosted and processed?

Core application infrastructure, databases, customer Blob storage, and PostgreSQL backup storage are hosted in Azure Central US. Auth0 uses a US tenant. Cloudflare traffic delivery and Azure Global model deployments have separate processing geographies.

Do AI workflows store prompts or responses?

Some evaluation workflows use stateful model responses and request response storage. Retention and deletion depend on the API feature and workflow. Contact us to review the processing requirements for your intended use.

How is access to customer information controlled?

Application access follows server-side workspace and project permissions, including checks for evaluation artifacts. Internal policy requires a documented business purpose and authorization for personnel access to customer content.

How are retention and deletion handled?

Retention follows the applicable agreement and operational requirements for each data store. Deletion scope includes application data, artifacts, provider data, logs, and backup expiration. Storage recovery windows are distinct from permanent erasure timelines. Contact us to agree on requirements for your deployment.

What recovery evidence is available?

A PostgreSQL restore exercise was documented, including schema checks, representative row counts, and read/write validation. Recovery objectives for a deployment should be discussed separately from this historical exercise.

How can we request supporting documentation?

Send the document names or your security questionnaire to [email protected]. We can discuss the relevant scope and supporting evidence. Internal policies and detailed operational evidence are shared through a reviewed request.

How can we report a security concern?

Email [email protected] with the affected feature, potential impact, and reproduction steps. Omit credentials and sensitive customer data from the initial message.