Security

Your docs stay yours.

CoTeam is built for teams that handle sensitive compliance and technical documentation. Here is exactly how we protect your data.


Core commitments

Private by default

Your knowledge base, questions, answers, and questionnaire files are isolated to your workspace. Row Level Security is enforced at the Supabase database layer on every table — not just in application code. No query can return data from another workspace, even with a misconfigured API call.

We never train on your data

Your documents, queries, and answers are never used to train any AI model — ours or our providers'. Anthropic (Claude) and OpenAI (embeddings) both operate under API terms that explicitly prohibit training on API inputs. Your proprietary content stays proprietary.

Encrypted end-to-end

All data in transit is encrypted with TLS 1.3. All data at rest — including KB chunks, embeddings, and questionnaire files — is encrypted with AES-256 managed by Supabase. Files are stored in private, access-controlled storage with time-limited signed URLs.

Full data control

Delete any document — all associated chunks and embeddings are removed immediately. Delete your workspace — all data is permanently erased within 24 hours. You own your data and can remove it at any time, no questions asked.


AI providers

CoTeam uses two AI providers. Here is what each does and what data they see.

Anthropic — Claude

Privacy policy →

Used for

Generates answers and questionnaire responses

What they see

Relevant KB excerpts (selected chunks, not your full KB) plus the question being answered. No personal information, no workspace metadata.

Anthropic API terms prohibit training on API inputs

OpenAI — Embeddings

Privacy policy →

Used for

Converts documents into vector representations for semantic search

What they see

Document text chunks during ingestion only. No questions, no answers, no user data.

OpenAI API terms prohibit training on API inputs

Infrastructure

Database

Supabase (Postgres)

Row Level Security on every table. EU or US region on request.

API / backend

Fly.io

Isolated machines per service. Private internal networking.

Frontend

Vercel

Edge network. No user data processed at the edge.

File storage

Supabase Storage

Private buckets. Time-limited signed URLs for download access.

Email

Resend

Transactional only. No marketing tracking pixels.

Payments

PayPal

We never touch or store payment card details.


Access control and authentication

Authentication

Powered by Supabase Auth. Email and password with email verification. Magic links available.

Roles

Owner, Admin, and Member. Owners control billing and can delete the workspace. Admins manage members and the knowledge base. Members can ask questions and process questionnaires.

Invitations

Team members join via a time-limited email invitation (7-day expiry). Pending invitations never grant access — only accepted invitations create workspace membership.

Extension tokens

The Chrome extension authenticates with a 30-day scoped token generated from a logged-in session. Tokens are stored in chrome.storage.local, never in page context, and are revocable by signing out.

SME review links

Magic links for external SME review expire in 5 days and are single-purpose — they only grant access to the specific questionnaire answers they were issued for, nothing else.

Questions about security?

We respond personally. No support ticket system, no bot.

Email founders@coteamai.com →