Security

Read-only by design. Private by architecture.

We only ever read what's public, we never touch anything behind a login, and your research never leaves a trace on the other side.

read_only
no follows
no view receipts

Read-only

Look at anyone, notify no one. No follows, no leaderboards.

public_only
no auth
public surfaces

Public sources only

No logins, no scraping behind auth, no private data.

tenant
isolated
your data

Tenant isolation

Your set, your brief, your history — scoped to your org.

sources
kept + timestamped
verifiable

Auditable

Every stored claim keeps the public artifact and the time we fetched it.

What we collect

The engine reads public surfaces: changelogs, blogs, careers pages, pricing pages, GitHub, ATS boards, Hacker News, Bluesky and news. It holds no credentials for anyone else's systems, so there is nothing behind a login it could reach. Tracking is one-directional — the companies you watch are never contacted, notified or given any signal that you exist.

Data handling

Everything the engine stores traces to a public artifact we fetched, with a timestamp. We keep the source so any claim is verifiable — and so anything can be deleted on request. We don't sell data, and we don't compile personal information.

Why the risk surface is small

The strongest thing we can say about security isn't a policy — it's the architecture. We ask for no third-party credentials, we ingest nothing from behind an authentication wall, and we store no private data about the companies in your set. There is very little to leak because there is very little collected.

If your review process needs specifics — how a given source is fetched, what we retain, where it's stored — ask us and we'll answer directly and in detail.

Questions?

Talk to us about security.