Secret Advisor
Trust center

Security

Secret Advisor is built so your business data stays yours. Every client runs on their own private server in the EU, the thinking runs through one sealed AI vendor pinned to your box, and nothing goes to your customers without your approval. This page is the honest, current picture, with the proof behind each claim.

Request our security package

Least access. Approval-gated public actions. Reviewable output.

Last verified 2026-07-23


Isolation

One private server, never a shared pool

Every client gets their own sealed server. Your Brain, your work, and your numbers live only there.

  • Your business runs on its own private server, never pooled with another company in a shared database.
  • There is no path from one company data to another. The isolation is built in, not promised.

Your AI

A sealed AI vendor, pinned to your box

The thinking runs through one sealed AI rail per box. It is pinned to specific models and isolated to your box. New boxes run on a sealed xAI Grok rail.

  • Your box talks to exactly one approved AI vendor, pinned to specific models. There is no model roulette and no silent vendor swap.
  • Your box uses its own sealed account with the AI vendor. Your prompts are never mixed with another client.
  • Each box carries a spend cap with alerts, so a runaway process cannot quietly run up cost.

Approvals

Nothing goes to your customers without your yes

Your agents prepare drafts. Anything public or irreversible waits for your approval.

  • Research, drafts, briefs, and recommendations are prepared without publishing anything. Publishing a page, posting, or sending outreach waits for your approval.
  • Autonomous publishing stays dark until you arm it yourself.

Access

Least access, and the work stays reviewable

Access starts from the workflow, not from a list of tools. An agent gets only the access the job needs, public actions stay approval-gated, and the output stays reviewable.

A content agent does not need sending rights. A research agent does not need to publish. An operations agent that reads internal context gets tighter boundaries. The access matches the job.

Every agent shows its source, its output, and the next action, so you can accept, edit, or reject. The goal is useful work you can trust, not blind autonomy.


Data residency

Your data stays in the EU

  • Your sealed server sits in EU data centers, in Germany and Finland. (Hetzner)
  • Site analytics are pinned to the EU and are anonymous and cookie-free.
  • The website and its data proxy run on Cloudflare, so the read token never reaches your browser.

Your rights

GDPR: your data, and your rights over it

This is a plain statement of alignment, not a badge. You keep clear rights over your data.

  • We align with the GDPR: lawful, minimal processing and clear data-subject rights. It is a statement of how we operate, never a certificate.
  • See and export: you can view the facts your agents hold and export your whole Brain to a portable file you own, in one tap. No lock-in.
  • Correct: you can correct or remove any single fact your agents keep.
  • Delete: cancel and your box and everything on it are destroyed within the retention window below.

CCPA

We never sell or share your personal information

  • Under the CCPA and CPRA we act as a service provider. We never sell or share your personal information. This is a statement of how we operate, not a badge.

Payments

Card details never touch our servers

  • Payments run on Stripe-hosted pages. Your card details go straight to Stripe and never touch our servers. Stripe is certified PCI DSS Level 1.

Certifications

Certifications, stated honestly

Here is the honest picture. We hold no certificate of our own yet. We inherit the certificates our infrastructure vendors hold, named and linked below. None are in progress today. The day a real deal needs SOC 2 or ISO 27001, this table gains an In progress row with a date.

StatusCertificateHeld byCoversVerified
InheritedISO 27001:2022HetznerThe EU data centers your server runs in (Nuremberg, Falkenstein, Helsinki)2026-07-23
InheritedBSI C5 Type 2HetznerGerman federal cloud-security criteria for those data centers2026-07-23
InheritedISO 27001, ISO 27018, SOC 2 Type IICloudflareThe layer that serves this site and the data proxy2026-07-23
InheritedSOC 2 Type 2xAIThe standard sealed AI rail for new boxes2026-07-23
InheritedPCI DSS Level 1StripeThe payment pages (cards never reach our servers)2026-07-23

Subprocessors

The services we rely on to run the product

Every outside service Secret Advisor relies on to run your box and the product, what each one touches, where, and why. Kept current, and each one sees only what it needs.

ServiceWhat it touchesWhereWhy
HetznerYour sealed box and its data at restEU (Germany, Finland)The private server your box runs on
CloudflareSite traffic and the data proxy (no Brain data stored)Global edge networkServes the site and the token-injecting proxy
xAIYour prompts and the replies, at the moment of thinkingUSThe standard sealed AI rail for new boxes
OpenAI Earlier client railPrompts and replies, at the moment of thinkingUSThe AI rail for clients onboarded before the xAI default
ComposioThe access token for a tool you connect, scoped to youComposio cloudHolds connected-account tokens, one customer sealed from every other
ApifyPublic web pages an agent is asked to readApify cloudFetches public web data for research
SlackYour chat with the Advisor and your agentsSlack cloudThe chat channel where the work happens
StripeYour billing details and card dataStripe (PCI DSS Level 1)Subscription billing; cards never touch our servers
PostHogAnonymous, cookie-free site analyticsEU (eu.i.posthog.com)Counts visits; holds no personal data
Resend Dormant, not yet activatedOutbound notification email, when activatedResend cloudNotification email

Retention

Cancel any month, and leave clean

  • Cancel any month. There is no lock-in.
  • Export any time before destruction. On cancellation your Brain is exported to a portable vault you own.
  • Your sealed box and everything on it are destroyed within 30 days of cancellation.

Practices

Security practices we can prove today

We list only the practices we can prove. As box-level verification completes, this list grows. We do not list a control before we can show it.

  • Secrets and keys are never committed to our code. A sealed check blocks any deploy that would leak one.
  • Every deploy passes gates, and a watchdog plus a canary page us if a box drifts.
  • Each client box uses its own keys. There is no shared login across clients.

Security package

Request our security package

Need more for a procurement review? Ask for our security package: this architecture in one document, our subprocessor detail, a data processing agreement, and our standard contractual clauses. We reply fast.


Questions buyers ask about trust and security

Where is my data stored?

On your own private server in EU data centers, in Germany and Finland. It is never pooled with another company data.

What AI runs my box?

Your box uses one sealed AI vendor, pinned to specific models, with its own account isolated to you. New boxes run on a sealed xAI Grok rail. Each vendor publishes its own data-handling terms.

Are you certified?

We hold no certificate of our own yet. We inherit the certificates our infrastructure vendors hold (Hetzner, Cloudflare, xAI, Stripe), listed above with links. We never imply their certificate is ours.

What happens if I leave?

Cancel any month. Your Brain exports to a portable file you own, and your sealed box and everything on it are destroyed within 30 days of cancellation.