Security & compliance
Your pipeline is your business. We treat it that way.
GDPR and privacy
- A Data Processing Addendum with the EU Standard Contractual Clauses and the UK Addendum is part of our terms for every customer.
- EU data residency in Frankfurt (AWS eu-central-1) is available on Scale.
- We list every subprocessor and give 30 days’ notice of changes.
- Data subject requests: r+pellwood-privacy@haggl.ai. We answer within 30 days.
Infrastructure
- Hosted on AWS in us-east-1 (default) or eu-central-1, with encrypted backups in a second region every hour and point-in-time recovery for 35 days.
- Encryption in transit (TLS 1.2+) and at rest (AES-256). Mailbox OAuth tokens are encrypted with per-workspace keys in AWS KMS.
- Production access is limited to on-call engineers, through SSO with hardware keys, and every session is logged.
Application security
- Responsible disclosure: report vulnerabilities to r+pellwood-security@haggl.ai. We acknowledge within one business day and do not pursue good-faith researchers.
- SAML SSO, SCIM, field history and audit logs on Scale. Google and Microsoft sign-in with enforced two-step verification on every plan.
The Assistant and your data
The Assistant runs on large language models from our listed subprocessors under zero-data-retention terms. Customer data is never used to train models, ours or theirs. Admins can turn the Assistant off per workspace or per team.