Security & Trust

What we do to protect customer data across GreatRouter, GreatStudios, and GreatChat — and what we honestly cannot claim yet. Security and privacy are part of how the platform is engineered, not a marketing line.

Six controls, applied consistently

The baseline that applies across all three products.

Encryption

TLS 1.3 for data in transit on every product. AES-256 at rest where supported by the underlying storage layer. HTTP Strict Transport Security across all marketing and product domains.

Access controls

Organization-scoped accounts with role-based access — Owner, Admin, Member, Viewer — and granular project permissions in GreatChat. API keys are scoped per workspace in GreatRouter.

Audit logging

Workspace-level audit logs for authentication events, billing changes, API key rotations, and configuration changes. Exportable on Enterprise plans.

Data residency

US and EU regions for product data on supported plans. Custom residency available for Enterprise. Regional metadata is documented per workspace.

Compliance posture

We follow industry best practices for privacy and data handling. We do not list certifications we have not legally verified. Specific posture details available on request for procurement teams.

Incident response

On-call rotation with runbooks for production incidents. Customers are notified within reasonable timelines as required by applicable law and our customer contracts.

How a request flows through the system

A single conceptual diagram. Every product follows the same path.

  1. 01

    You submit a request

    Through GreatStudios, GreatChat, or directly via the GreatRouter API. Authentication uses your workspace credentials.

  2. 02

    GreatRouter routes the request

    The router classifies intent and selects the right model. The request is signed and sent to the inference provider over TLS.

  3. 03

    The model responds

    Inference happens inside the provider's environment. Responses are streamed back through GreatRouter and surfaced in the product.

  4. 04

    Results are stored in your workspace

    Outputs, generations, and chat history live in your workspace storage (Neon Postgres + R2). Only your team can access them, subject to role-based permissions.

Storage uses Neon Postgres (relational) and Cloudflare R2 (object) inside your workspace boundary. Provider names referenced here are the underlying database and object store; we do not name the inference platform in customer-facing product UI.

What we will not do with your data

Six commitments we hold ourselves to.

No training on your data

Your prompts, documents, and generated content are not used to train our models or any third-party model. Inference passes through providers but is not retained for training.

No selling of personal data

We never sell or rent personal data. We share data with payment processors and AI model providers strictly to deliver the service you've requested.

Data deletion on request

Customers can request deletion of their account and associated data. We honor requests in line with applicable law (GDPR, CCPA, and equivalents).

GDPR and CCPA aware

Our Privacy Policy documents the legal basis for processing, retention windows, and your rights as a data subject. See the policy for jurisdiction-specific notices.

Regional data residency

Customer data can be pinned to US or EU regions on supported plans. Custom residency is available under Enterprise agreements.

Transparent retention

Default retention is the lifetime of your account plus a reasonable window for billing, security, and legal obligations. Specific retention details are documented per product.

Honest about what we have — and haven't — verified

Our current compliance posture includes verifiable practices and operational controls, not aspirational marketing claims. We do not advertise certifications we have not legally completed.

  • TLS 1.3 enforced across product and marketing domains.
  • Workspace-scoped authentication with role-based access controls.
  • Encryption at rest where supported by the underlying storage layer.
  • Internal access to production data is limited and logged.
  • Periodic dependency audits and timely patching of security-relevant updates.
  • Documented incident response runbooks and on-call rotation.
For procurement teams

Need detailed information for a vendor security review? Write to security@greatstudiosai.com with your timeline and questionnaire format. We respond promptly during business days.

Report a vulnerability

If you believe you have found a security issue in any Greatapps product, please email security@greatstudiosai.com with steps to reproduce. We thank reporters who follow coordinated disclosure and do not act in bad faith.

Related: Privacy Policy · Terms of Service · Cookie Policy