Legal, last updated October 2026

Security

Superaligned reads data from the tools your team connects. This page says how that data is protected today. It describes what the service does now, not what we plan to do.

Hosting

  • The application runs on Vercel. All traffic is served over HTTPS.
  • Data is stored in a Neon Postgres database in the EU region.
  • The current list of third parties is at /legal/subprocessors.

Connected tools

  • Each connection uses the provider's own OAuth flow or an API key you create in that provider. We never ask for your password to another service.
  • Access and refresh tokens are encrypted at rest with AES-256-GCM before they are stored. The encryption key is held outside the database.
  • Connections read the sources you pick. Some also request write access so Superaligned can file an issue or post a comment from a decision.
  • Incoming webhooks from GitHub, Linear and Slack are verified against each provider's signing secret before they are processed.
  • You can disconnect a source at any time. Revoking the app in the provider also stops all access.

Workspaces and access

  • Sign-in uses Google. We do not store passwords.
  • Every workspace has its own data. Content is never shared across workspaces, even for a user who belongs to more than one.
  • Members have one of three roles: owner, admin or member. Only owners and admins can connect or disconnect sources.

Models

  • Workspace content is sent to a language model only when the pipeline or the agent needs it to produce a claim, a recommendation or a reply.
  • We do not train models on your workspace content.

Deletion

To delete a workspace and the data pulled into it, or to request an export, write to the address below.

Reporting a vulnerability

Write to team@superaligned.to with the details and steps to reproduce. We reply within 2 business days. Please do not access other customers' data or degrade the service while testing. We will not take action against good-faith research that follows these rules.