Security
CoTeam is built for teams that handle sensitive compliance and technical documentation. Here is exactly how we protect your data.
Your knowledge base, questions, answers, and questionnaire files are isolated to your workspace. Row Level Security is enforced at the Supabase database layer on every table — not just in application code. No query can return data from another workspace, even with a misconfigured API call.
Your documents, queries, and answers are never used to train any AI model — ours or our providers'. Anthropic (Claude) and OpenAI (embeddings) both operate under API terms that explicitly prohibit training on API inputs. Your proprietary content stays proprietary.
All data in transit is encrypted with TLS 1.3. All data at rest — including KB chunks, embeddings, and questionnaire files — is encrypted with AES-256 managed by Supabase. Files are stored in private, access-controlled storage with time-limited signed URLs.
Delete any document — all associated chunks and embeddings are removed immediately. Delete your workspace — all data is permanently erased within 24 hours. You own your data and can remove it at any time, no questions asked.
CoTeam uses two AI providers. Here is what each does and what data they see.
Used for
Generates answers and questionnaire responses
What they see
Relevant KB excerpts (selected chunks, not your full KB) plus the question being answered. No personal information, no workspace metadata.
Used for
Converts documents into vector representations for semantic search
What they see
Document text chunks during ingestion only. No questions, no answers, no user data.
Database
Supabase (Postgres)
Row Level Security on every table. EU or US region on request.
API / backend
Fly.io
Isolated machines per service. Private internal networking.
Frontend
Vercel
Edge network. No user data processed at the edge.
File storage
Supabase Storage
Private buckets. Time-limited signed URLs for download access.
Resend
Transactional only. No marketing tracking pixels.
Payments
PayPal
We never touch or store payment card details.
Powered by Supabase Auth. Email and password with email verification. Magic links available.
Owner, Admin, and Member. Owners control billing and can delete the workspace. Admins manage members and the knowledge base. Members can ask questions and process questionnaires.
Team members join via a time-limited email invitation (7-day expiry). Pending invitations never grant access — only accepted invitations create workspace membership.
The Chrome extension authenticates with a 30-day scoped token generated from a logged-in session. Tokens are stored in chrome.storage.local, never in page context, and are revocable by signing out.
Magic links for external SME review expire in 5 days and are single-purpose — they only grant access to the specific questionnaire answers they were issued for, nothing else.
We respond personally. No support ticket system, no bot.
Email founders@coteamai.com →