Your data stays yours
Encryption, isolation, and compliance built in. Here is what you get, in plain English.
Encryption everywhere
HTTPS with TLS 1.2+ in transit. AES-256 at rest. Secrets encrypted again before storage.
Workspace isolation
Every query is scoped to your workspace at the database level. No cross-workspace leaks.
External sign-in
We use an external auth provider. No passwords stored on our servers.
Audit logging
Every AI assistant call is logged for you to review. Production access is logged monthly.
Compliance built in
Unsubscribe links, consent records, do-not-call lists, and calling hours enforced.
72-hour breach notice
If a breach ever happens, we notify affected users and authorities within 72 hours.
What we never do
- We never sell your data, your leads, or your activity.
- We never store passwords on our servers.
- We never send cold emails from our own servers.
- We never ignore consent, the do-not-call list, or calling hours.
Compliance
CAN-SPAM: one-click unsubscribe and your physical address in every email.
GDPR: data export and account deletion on request.
TCPA: AI voice calls only run with prior written consent.
DPA: available at /dpa.
Security contact
Found a vulnerability? Email security@baddecision.app. We respond within 48 hours.