Skip to main content

Security & App Security Guidelines

This page explains how Statisfy protects your data and the settings we recommend so your workspace and integrations stay secure.
To report a security issue, email support@statisfy.com with “Security” in the subject line. See Reporting a security issue.

How Statisfy protects your data

Compliance

Statisfy is SOC 2 compliant. Compliance documentation is available in our Trust Center.

Encryption

  • In transit: all traffic uses HTTPS. HTTP requests are redirected to HTTPS, and connections require TLS 1.2 or higher with Google-managed certificates.
  • At rest: data in Google Cloud is encrypted at rest by Google Cloud’s default encryption.

Tenant isolation

Each organization’s data lives in its own database schema, and every request is scoped to your organization through your signed-in session. This keeps each organization’s data separate from every other organization’s.

Authentication and access control

  • Sign-in is handled by Clerk. Every request is verified against a signed session token.
  • Access is role-based: admin, builder, integration admin, member, and viewer roles control which features each user can see and change. See User management and roles.
  • Single sign-on is available. See Setting up Okta SSO.
  • Customer portals use passwordless sign-in (one-time codes and magic links). Codes are stored only as one-way hashes and are never logged.

AI and your data

  • Statisfy uses foundational large language models (LLMs), such as Google Gemini (Vertex AI), Azure OpenAI, and Anthropic Claude, to power AI features.
  • As stated in our Privacy Policy, Statisfy does not use customer data to train, fine-tune, or develop AI or machine-learning models.
  • AI-generated answers can be inaccurate. Review them before you share or act on them.

File uploads and external connections

  • Uploaded images are limited to allowed file types and 10 MB, and file names are sanitized.
  • Custom MCP servers must use HTTPS, and addresses that point to private or internal networks are rejected.
Follow these practices to keep your Statisfy workspace secure.
Assign the viewer or member role by default, and reserve admin and integration admin for the people who manage settings and integrations. Review roles regularly in User management.
Remove departed users from your organization right away, and rotate any API keys or integration credentials they created or had access to.
Sign in through your identity provider so your company’s password, MFA, and offboarding policies apply to Statisfy. See Setting up Okta SSO.
  • Create a separate key for each integration or script.
  • Rotate keys regularly.
  • Never commit keys to source control or paste them into chat or tickets.
  • Revoke a key immediately if you think it was exposed.
Store API keys and passwords that automations need in the Secret Store rather than in prompts, notes, or workflow text.
When you connect an integration, choose only the permission sets you need. Disconnect integrations you no longer use so their access is revoked.
Add custom MCP servers only from providers you trust, and use credentials scoped to what Statisfy needs.
AI-generated summaries, drafts, and answers can be wrong. Check them before sending them to customers or using them for decisions.

Reporting a security issue

If you believe you’ve found a security vulnerability in Statisfy:
  1. Email support@statisfy.com with “Security” in the subject line.
  2. Include a description of the issue, the steps to reproduce it, and the affected URL or feature.
  3. Don’t access or change other customers’ data, and don’t publicly disclose the issue until we’ve had a chance to fix it.
We aim to respond within 3 business days.