Your data stays yours

Encryption, isolation, and compliance built in. Here is what you get, in plain English.

Encryption everywhere

HTTPS with TLS 1.2+ in transit. AES-256 at rest. Secrets encrypted again before storage.

Workspace isolation

Every query is scoped to your workspace at the database level. No cross-workspace leaks.

External sign-in

We use an external auth provider. No passwords stored on our servers.

Audit logging

Every AI assistant call is logged for you to review. Production access is logged monthly.

Compliance built in

Unsubscribe links, consent records, do-not-call lists, and calling hours enforced.

72-hour breach notice

If a breach ever happens, we notify affected users and authorities within 72 hours.

What we never do

  • We never sell your data, your leads, or your activity.
  • We never store passwords on our servers.
  • We never send cold emails from our own servers.
  • We never ignore consent, the do-not-call list, or calling hours.

Compliance

CAN-SPAM: one-click unsubscribe and your physical address in every email.

GDPR: data export and account deletion on request.

TCPA: AI voice calls only run with prior written consent.

DPA: available at /dpa.

Security contact

Found a vulnerability? Email security@baddecision.app. We respond within 48 hours.