Trust center

An AI team only works if you can hand it real responsibility. Here is exactly how your data — and your customers' data — is protected.

Privacy-first by design

Consent-first messaging and data-subject rights handled by default — privacy built in, not bolted on.

SOC 2 Type II

Independently audited controls across security, availability and confidentiality. Report available under NDA.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. Customer conversation data is never used to train shared models.

Append-only audit log

Every agent action recorded — who asked, what ran, what it cost. Exportable at any time, on every plan.

Access controls

Role-based access, SSO/SAML on Scale, and least-privilege access for our own staff with full logging.

Data residency

Gulf-region hosting by default; in-Kingdom residency available for Saudi enterprises on request.

Our commitments, in plain language

No legal maze. These are the promises we make to every business on Gridwork, and they don't change with your plan.

Your data is yours — export it or delete it entirely, any time
Agents never invent prices, availability or policies
No customer messages are ever sold or shared with third parties
Spend caps are hard limits enforced in code, not guidelines
A human at Gridwork is reachable within one business day, always

Security questions?

Our security team answers vendor reviews, DPAs and audit requests within two business days.

security@bygridwork.com

Hand it real responsibility

Start with everything in ask-first mode, watch every action in the audit log, and loosen the reins only as you build trust.

Start freeTalk to security
Free for 14 days · No card needed · Cancel anytime