Adze Legal

Security

Built to handle your business knowledge with care.

Adze learns your business and drafts on your behalf — so the data you trust us with matters. We encrypt it, minimize it, and never use it to train foundation models.

Data handling

What we store, and how

Encrypted chat & credentials

Chat content, connected-account credentials, MFA secrets, and stored IP/user-agent values are encrypted at the field level with AES-256-GCM — on top of full encryption at rest.

Minimal footprint

We collect only what we need to run the Service. Raw crawled and collected content is kept only transiently (roughly 30 days) before deletion or archival.

Scoped to your organization

Every record is partitioned by organization. Access within your team is governed by role-based controls (owner, admin, member, viewer).

Clean deletion

Closing your account starts a 30-day grace period, after which data is permanently deleted across all stores, subject to legal retention obligations.

AI & your data

Your knowledge isn't training data

Adze sends relevant business knowledge and prompts to large language model providers to generate content on your behalf. We treat that data as yours.

  • No model training. We do not use your business knowledge, chat content, or generated content to train foundation models.
  • Providers can't train either. Our AI providers (Anthropic, OpenAI, and Google Gemini) are contractually prohibited from training on data sent through their APIs.
  • Learning stays in your tenant. The learning loop that improves drafts over time operates only within your organization's own data.
  • Human-in-the-loop. Community and social drafts are presented for your review — nothing is posted on those channels without your action.

Infrastructure

Where things run

  • Hosting: Hetzner Online GmbH (Germany) with Amazon Web Services (United States / EU) for object storage, CDN, and transactional email.
  • Encryption in transit: TLS 1.2+ on all external connections.
  • Encryption at rest: Databases, backups, and object storage are encrypted at rest, with field-level encryption layered on sensitive values.
  • Network isolation: Production systems are segmented behind firewalls and security groups with restricted access.
  • Patch management: Regular updates to operating systems, dependencies, and application code.

Access control

Authentication & access

Your account

  • Session-based authentication with secure, server-side sessions. Passwords are stored only as salted bcrypt hashes.
  • Optional multi-factor authentication (TOTP and WebAuthn) with recovery codes, plus Google sign-in.
  • Role-based access control for Authorized Users within your organization.

Our systems

  • Multi-factor authentication required for all administrative access to production.
  • Unique accounts for all personnel — no shared credentials.
  • Principle of least privilege, with audit logging across internal systems.

Compliance

Legal & regulatory

Adze is operated by AltaCoda LLC, a Delaware limited liability company. We comply with applicable data protection laws including GDPR and CCPA/CPRA.

  • GDPR. We act as a data processor when handling personal data on your behalf. Our DPA includes Standard Contractual Clauses (Module 2) for EEA, UK, and Swiss data transfers. Sub-processor list published at adze.cloud/subprocessors.
  • CCPA/CPRA. We do not sell or share personal information. Our DPA includes CCPA service-provider certification.
Document Link
Terms and Conditions adze.cloud/terms
Privacy Policy adze.cloud/privacy
Data Processing Addendum adze.cloud/dpa
Sub-processor list adze.cloud/subprocessors

Incident response

When things go wrong

  • Documented procedures for identifying, containing, and remediating security incidents.
  • Personal Data Breach notification within 72 hours, as required by GDPR and committed in our DPA.
  • Post-incident review and remediation for all security events.

Vendor management

Sub-processor oversight

  • Due diligence on all sub-processors before engagement, evaluating their security and data-protection controls.
  • Contractual data-protection obligations imposed on every sub-processor.
  • 30-day advance notice of sub-processor changes, with objection rights for customers.
  • Full sub-processor list published at adze.cloud/subprocessors.

Responsible disclosure

Found a vulnerability?

We're grateful to security researchers who help keep Adze safe. If you've found a vulnerability, please reach out privately before public disclosure.

  • We acknowledge reports within 2 business days.
  • We work to understand and validate the reported issue.
  • We will not take legal action against researchers acting in good faith.
  • We ask for reasonable time to remediate before public disclosure.

Transparency

What we don't do

  • We don't use your data to train foundation models.
  • We don't sell or share your personal information.
  • We don't post to community or social channels without your approval.
  • We don't store full payment card numbers.
  • We don't access connected services beyond the scopes you grant.
  • We don't retain raw collected content longer than we need it.