Trust Center
UpdatedReview our security controls, service providers, policies, and technical documentation. For supporting evidence or a security questionnaire, contact our security team.
Controls
Evidence methods and dates apply to the scope described in each row. “Verified” refers to the dated internal check shown. “Adopted” identifies an established policy or procedure. “Reviewed” describes a document review; local tests are labelled separately.
Infrastructure
| Control | Evidence |
|---|---|
| Core hosting Application and database AKS clusters, customer Blob storage, and PostgreSQL backup storage are hosted in Azure Central US. AI processing has a separate service scope. | VerifiedConfiguration checked |
Data protection
| Control | Evidence |
|---|---|
| Object and backup encryption Customer files and PostgreSQL backups in the inspected Azure Blob accounts use Microsoft-managed encryption at rest. | VerifiedConfiguration checked |
| Database disk encryption The inspected database-cluster managed disks use platform-managed encryption keys. | VerifiedConfiguration checked |
| Storage transport and public access Customer and backup Blob accounts require HTTPS with TLS 1.2 or newer and have public Blob access disabled. This control applies to these storage accounts. | VerifiedConfiguration checked |
| Retention and erasure requirements Our procedure requires deletion scope to account for application records, artifacts, model-service data, logs and backups, including reapplication after restoration. Completion periods depend on the agreed scope and verified workflow. | AdoptedProcedure adopted |
| Browser privacy signals Website analytics suppression for Global Privacy Control and Do Not Track has passed local tests. Deployment verification is pending; this evidence applies to the tested website change. | Tested locallyLocal implementation tests |
Access control
| Control | Evidence |
|---|---|
| Workspace and project authorization Server-side checks govern workspace administration and project access. Project permissions can be assigned to users or workspace groups. | VerifiedImplementation reviewed |
| Evaluation artifact access File, preview, and thumbnail access is checked against the authenticated workspace, project permissions, and deletion status. An artifact address alone does not grant access. | VerifiedImplementation reviewed |
| Workspace credentials Workspace credentials use AES-GCM envelope encryption. Management responses expose metadata and masked hints; runtime resolution checks execution context, expiry, and active grants. | VerifiedImplementation reviewed |
| Key Vault protections Production Azure Key Vault has role-based access control, purge protection, and 30-day soft deletion enabled. | VerifiedConfiguration checked |
| Workload identity Workload identity is enabled on the application AKS cluster. This configuration is separate from human administrator access controls. | VerifiedConfiguration checked |
Recovery and operations
| Control | Evidence |
|---|---|
| Storage recovery protections Customer and backup Blob accounts have versioning and 30-day soft deletion enabled. Recovery protection periods are distinct from customer erasure timelines. | VerifiedConfiguration checked |
| Database restoration tested A backup was restored into an isolated test cluster. The documented exercise checked schemas, representative row counts, and read/write behavior. | VerifiedRestore documented |
| Credential-access events The workspace secret service records runtime access and denied-access events with execution context. Recognized signed storage URLs are sanitized in application logging. | VerifiedImplementation reviewed |
| Operational log retention The production Azure Log Analytics workspace is configured with 30-day retention. | VerifiedConfiguration checked |
Governance and policies
| Control | Evidence |
|---|---|
| Security governance IS-01 establishes accountable ownership, policy maintenance, evidence reviews, and tracking of implementation gaps and exceptions. | AdoptedPolicy adopted |
| Access lifecycle and personnel IS-02 requires individual accounts, least privilege, privileged-access approval, quarterly access reviews, departure access removal, and confidentiality obligations. | AdoptedPolicy adopted |
| Information handling and deletion IS-03 defines restricted information and requirements for retention inventories, authorized deletion requests, downstream reconciliation, and backup treatment. | AdoptedPolicy adopted |
| Supplier and AI processing reviews IS-04 requires a provider inventory, approval before new processing, review of data scope and retention terms, and annual supplier reviews. | AdoptedPolicy adopted |
| Secure development and infrastructure IS-05 defines security review and validation of changes, credential handling, vulnerability triage, and infrastructure protection requirements. | AdoptedPolicy adopted |
| Incident response IS-06 defines reporting, incident ownership, containment, evidence preservation, recovery, communications, and exercise requirements. | AdoptedPolicy adopted |
| Backup and continuity responsibilities IS-07 requires backup review, documented recovery procedures, isolated restore exercises, and measurement of recovery objectives. | AdoptedPolicy adopted |
| SOC 2 readiness program Our Security readiness program defines the system scope, maps controls to the Common Criteria, and maintains a risk assessment, evidence register, and operating review procedures. | ReviewedProgram documented |
| Privacy-request handling Our procedure covers identity and authority checks, access, correction and deletion requests, customer-controller routing, deadlines, and evidence of completion. Requests can be sent to [email protected]. | AdoptedProcedure adopted |
| Processing and supplier inventory An internal register documents core hosting, identity, AI processing, operational records and recovery storage, with data scope, retention questions and follow-up reviews for optional integrations. | ReviewedRegister reviewed |
Subprocessors
Core service providers and their processing roles. Request the complete processor scope for your intended workflows, including optional integrations.
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| Microsoft Azure | Application hosting, databases, storage, backups, and AI processing | Customer content and application data; prompts and responses for AI workflows. | Core infrastructure: Central US. AI resources: Central US and East US; Global deployments may process across supported geographies. |
| Auth0 (Okta) | User authentication and identity management | Account and identity information used for authentication. | US tenant hosting. |
| Cloudflare | DNS, proxying, and traffic delivery for websites and customer application/API traffic | Requests, responses, and associated network metadata for proxied traffic, including streaming connections. | Global network. Core Azure hosting location does not restrict all edge processing. |
Teammately operates supporting services within its Azure infrastructure, including PostgreSQL managed with CloudNativePG and self-hosted Umami analytics. These software projects are not separate service providers receiving customer data.
Resources
Technical summaries and policy information for your review. Each summary describes its own scope.
Technical documentation
Architecture and customer data flowsCore hosting, identity, application traffic, and AI boundariesRead summary
Customer application and API requests, including streaming responses, pass through Cloudflare to Teammately’s Azure application infrastructure. Auth0 provides identity authentication. The authenticated API boundary performs workspace and project authorization before routing work to internal services.
Application services and PostgreSQL run on Azure Kubernetes Service. Customer objects and database backups are stored in Azure Blob Storage. Core hosting is in Central US. AI processing and traffic delivery have separate geographic scopes.
Durable evaluation workflows are handled by backend workers. Depending on the workflow, customer content is included in prompts or files sent to model services. Customer-configured integrations should be reviewed as part of the deployment’s processing scope.
AI processing and customer data useTraining commitment, model processing, and response storageRead summary
Teammately does not use customer workspace data to train shared generative models without express written agreement. Processing customer content to perform a requested evaluation is separate from training a shared model.
The reviewed primary evaluation client requires an Azure OpenAI or Microsoft Foundry endpoint. Azure Global deployments may process prompts and responses across supported geographies. Some evaluation workflows request stored responses; retention must be assessed for the specific feature and workflow.
Microsoft’s AI data processing documentation describes service storage, model training terms, and abuse monitoring. Contact us to review the requirements for your selected workflows.
Access control and credential handlingWorkspace permissions, artifact authorization, and secretsRead summary
Application permissions are scoped to workspaces and projects. Artifact access checks include the authenticated workspace, project access, and deletion status. Possession of an artifact URL does not itself grant access.
Workspace credentials use envelope encryption and are managed separately from evaluation scripts. Management responses return metadata and masked hints. Runtime resolution checks execution context, expiration, and active grants. Azure Key Vault provides infrastructure secret access and recovery controls.
Internal policy requires an authorized business purpose for personnel access to customer content and records of access decisions. Product authorization and human infrastructure administration are distinct controls.
Backup and recoveryStorage protections and the documented restore exerciseRead summary
A PostgreSQL backup was restored into a separate test cluster. The recorded validation covered schema inventory, representative row counts, and read/write testing.
Customer and backup Blob accounts have versioning and 30-day soft deletion enabled. These protections help recovery; they do not define a guaranteed recovery objective or maximum data-erasure period.
Our internal policy establishes backup review and restore-test responsibilities. Discuss recovery objectives and deletion requirements with us for your deployment.
Internal policies
Teammately maintains internal policies governing the following areas. Adopted , they define responsibilities, review requirements, and how implementation gaps are tracked.
- IS-01 · Governance and responsibilities
- IS-02 · Access control and personnel security
- IS-03 · Information handling, retention and deletion
- IS-04 · Supplier and AI processing
- IS-05 · Secure development and infrastructure
- IS-06 · Incident response
- IS-07 · Backup and business continuity
Privacy requests and retentionRequest handling, customer instructions and erasure scopeRead summary
Our adopted procedure covers identity and authority verification, request ownership, response deadlines, customer-controller coordination and completion evidence. Contact [email protected] for access, correction, deletion or other privacy questions.
Retention and erasure reviews account for application records, files, model-service data, operational records and backups. Backup recovery periods are separate from permanent erasure timelines. Processing locations and optional integrations are reviewed for the intended customer workflow.
Legal documents
Frequently asked questions
How can I make a privacy request?
Email [email protected] to request access, correction or deletion, or ask a privacy question. These messages reach our accountable owner. We verify identity and authority as appropriate. For customer-controlled workspace data, we coordinate with the customer organization and act on its documented instructions.
Who is responsible for processing personal information?
Teammately Inc. is the contracting company. We process customer workspace content on the customer’s instructions. Our Privacy Policy describes our own processing for website, account and business administration. The applicable agreement and purpose determine the processing role.
What do the framework marks show?
The GDPR and CCPA / CPRA marks identify the privacy frameworks addressed by this page. The SOC 2 mark identifies our Security readiness program targeting a Type 2 examination, with readiness in progress. Individual controls describe their evidence, status and review date.
Is customer data used to train shared AI models?
Teammately does not use customer workspace data to train shared generative models without the customer’s express written agreement. Models used in workflows process data to provide the requested service. Provider processing and retention terms apply separately.
Where is customer data hosted and processed?
Core application infrastructure, databases, customer Blob storage, and PostgreSQL backup storage are hosted in Azure Central US. Auth0 uses a US tenant. Cloudflare traffic delivery and Azure Global model deployments have separate processing geographies.
Do AI workflows store prompts or responses?
Some evaluation workflows use stateful model responses and request response storage. Retention and deletion depend on the API feature and workflow. Contact us to review the processing requirements for your intended use.
How is access to customer information controlled?
Application access follows server-side workspace and project permissions, including checks for evaluation artifacts. Internal policy requires a documented business purpose and authorization for personnel access to customer content.
How are retention and deletion handled?
Retention follows the applicable agreement and operational requirements for each data store. Deletion scope includes application data, artifacts, provider data, logs, and backup expiration. Storage recovery windows are distinct from permanent erasure timelines. Contact us to agree on requirements for your deployment.
What recovery evidence is available?
A PostgreSQL restore exercise was documented, including schema checks, representative row counts, and read/write validation. Recovery objectives for a deployment should be discussed separately from this historical exercise.
How can we request supporting documentation?
Send the document names or your security questionnaire to [email protected]. We can discuss the relevant scope and supporting evidence. Internal policies and detailed operational evidence are shared through a reviewed request.
How can we report a security concern?
Email [email protected] with the affected feature, potential impact, and reproduction steps. Omit credentials and sensitive customer data from the initial message.