Security
A short overview of how we protect accounts, integrations, and customer data. Full details live in Privacy and the Data Processing Agreement.
Access and sessions
Signed-in sessions use an httpOnly cookie (`addecide_session`). Language preference is stored separately. Keep webhook HMAC secrets out of public clients. API keys (`addec_sk_…`) are not yet part of the live ingest flow.
Data handling
We minimize personal data in ingest wherever possible. Raw ingest is retained for 30 days, aggregated facts for 24 months, and invoices for 10 years under legal hold. Model training on Customer Content is off by default.
Subprocessors and incidents
Hosting, email, payments, and optional AI providers are listed in the Data Processing Agreement. If you need to report a security concern, email [email protected] with “security” in the subject.