Security & Trust

Your team's knowledge is valuable. Here's how we protect it.

How We Protect Your Data

Encryption

All data encrypted in transit (TLS 1.2+) and at rest (AES-256)

Authentication

Secure Google OAuth authentication with session management

Access Control

Team-based permissions ensure only authorized members can access data

Infrastructure

Hosted on Google Cloud Platform with enterprise-grade security

Privacy

We only access your data to provide the service, never for other purposes

Your Control

Export or delete your data anytime - you own your content

Where Your Data Lives

Google Cloud Platform

All data is stored on Google Cloud infrastructure, the same platform that powers Gmail, Drive, and YouTube. Google Cloud is SOC 2/3, ISO 27001, and HIPAA compliant.

Encryption Standards

In Transit: All data is encrypted using TLS 1.2+ (the same as online banking).
At Rest: All stored data is encrypted using AES-256 encryption.

Team Isolation

Your team's data is completely isolated. Only team members you explicitly invite can access your team's files and content. We enforce this at the database and storage level.

You Own Your Data

Export Anytime

Export all your team's data in markdown format with one click. No lock-in, no hassle.

Delete Anytime

Request deletion of your data at any time. We'll remove it from our systems within 30 days.

Access Controls

Manage who can access your team's data. Add or remove members anytime.

No Training Data

We never use your data to train AI models or for any purpose other than providing our service.

Compliance & Standards

GDPR

✓ Compliant

EU data protection compliance

HTTPS/TLS

✓ Compliant

All traffic encrypted

OAuth 2.0

✓ Compliant

Industry-standard auth

SOC 2 Type II

In Progress

Enterprise security audit

Our Commitment to Transparency

We believe in being honest and transparent about our security practices. We're continuously improving our security posture and will always be upfront about what we do and don't do.

What we do:

Encrypt all data, enforce team-based access controls, use secure authentication, host on enterprise infrastructure

What we're working on:

SOC 2 Type II certification, advanced audit logging, field-level encryption for sensitive data, multi-factor authentication

What to know:

Like most cloud services, we currently use provider-managed encryption keys. For zero-knowledge encryption, we recommend using local encryption before upload for highly sensitive data.

Best Practices for Your Team

  • 1
    Use strong Google account security:

    Enable 2-factor authentication on your Google account for added security.

  • 2
    Review team members regularly:

    Remove team members who no longer need access to your data.

  • 3
    Be mindful of sensitive data:

    Avoid uploading highly sensitive information like passwords, credit card numbers, or social security numbers.

  • 4
    Export regularly:

    Keep backups of your important data by exporting your team's context regularly.

Questions About Security?

We're happy to discuss our security practices in detail. Whether you're evaluating Feed Bob for your team or have specific security requirements, we're here to help.