Security and privacy
Your customers trust you with their details. Here's how Ember protects them, and how it helps you meet your own obligations.
Your data stays yours
- Each workspace is walled off at the database level (row-level security on every table), and we test those rules for every role.
- Data is encrypted in transit (TLS 1.2+) and at rest.
- Export your contacts as CSV at any time. Deleting a workspace deletes its data.
Accounts and access
- Two-step verification for everyone, required for admins before team changes, API keys, exports and privacy actions.
- Roles: owner, admin, member and read-only.
- API keys are stored only as hashes, shown once, scoped, and revocable instantly.
- An audit log records every change, by person, API key or agent. Nobody can edit or delete it.
- Ember's support team can't see your workspace unless an admin lets them in, for a limited time. Every support visit and change is shown to your admins.
Privacy law, handled
- For your contacts' data, Ember acts as your processor (GDPR) and service provider (CCPA), under a data processing agreement.
- Consent records keep the exact wording, the form version, the time and the source.
- Export, restrict, anonymize or delete a person in one click, with each request logged.
- Embedded forms set no cookies and don't track visitors, so they don't need a cookie banner.
Email done right
- Email goes through Bellow, The Smithy's sending service, on Amazon SES.
- Unsubscribes, bounces and complaints are suppressed automatically, and suppression survives deletion (as a one-way hash).
- Your postal address goes in the footer, and marketing email (coming with sequences) will require consent and a one-click unsubscribe.
AI, with people in charge
- Agent actions are labelled on every timeline and in the audit log.
- Lead scoring and summaries are suggestions; Ember never makes significant decisions about people on its own.
- Chat agents built on Ember must tell visitors they're talking to an AI.
Subprocessors
The services that process data for Ember. We give 30 days' notice before adding one.
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database and sign-in | United States |
| Netlify | Hosting | United States |
| Amazon Web Services (via Bellow) | Email delivery | United States |
Not supported: health records (HIPAA), card numbers, and data about children. Questions, or a security issue to report? Contact us.