Skip to content
Ember

Security and privacy

Your customers trust you with their details. Here's how Ember protects them, and how it helps you meet your own obligations.

Your data stays yours

  • Each workspace is walled off at the database level (row-level security on every table), and we test those rules for every role.
  • Data is encrypted in transit (TLS 1.2+) and at rest.
  • Export your contacts as CSV at any time. Deleting a workspace deletes its data.

Accounts and access

  • Two-step verification for everyone, required for admins before team changes, API keys, exports and privacy actions.
  • Roles: owner, admin, member and read-only.
  • API keys are stored only as hashes, shown once, scoped, and revocable instantly.
  • An audit log records every change, by person, API key or agent. Nobody can edit or delete it.
  • Ember's support team can't see your workspace unless an admin lets them in, for a limited time. Every support visit and change is shown to your admins.

Privacy law, handled

  • For your contacts' data, Ember acts as your processor (GDPR) and service provider (CCPA), under a data processing agreement.
  • Consent records keep the exact wording, the form version, the time and the source.
  • Export, restrict, anonymize or delete a person in one click, with each request logged.
  • Embedded forms set no cookies and don't track visitors, so they don't need a cookie banner.

Email done right

  • Email goes through Bellow, The Smithy's sending service, on Amazon SES.
  • Unsubscribes, bounces and complaints are suppressed automatically, and suppression survives deletion (as a one-way hash).
  • Your postal address goes in the footer, and marketing email (coming with sequences) will require consent and a one-click unsubscribe.

AI, with people in charge

  • Agent actions are labelled on every timeline and in the audit log.
  • Lead scoring and summaries are suggestions; Ember never makes significant decisions about people on its own.
  • Chat agents built on Ember must tell visitors they're talking to an AI.

Subprocessors

The services that process data for Ember. We give 30 days' notice before adding one.

ServicePurposeLocation
SupabaseDatabase and sign-inUnited States
NetlifyHostingUnited States
Amazon Web Services (via Bellow)Email deliveryUnited States

Not supported: health records (HIPAA), card numbers, and data about children. Questions, or a security issue to report? Contact us.