Your conversations and knowledge base deserve serious protection. Goldilocks is built with security at its core—not bolted on as an afterthought.
Independent audit of security controls covering confidentiality, availability, and processing integrity.
Built for global privacy requirements with data subject rights, consent management, and cross-border transfer protections.
California privacy compliance with data access, deletion, and opt-out capabilities.
All data transmitted over TLS 1.3. No unencrypted connections accepted.
All stored data encrypted using AES-256. Encryption keys managed through Cloud KMS.
Complete tenant isolation at the database level. Your data is never mixed with other accounts.
When you delete data or close your account, it's permanently removed from all systems.
Hosted on Google Cloud Platform with enterprise-grade security, redundancy, and availability.
Private networking, firewall rules, and DDoS protection. No public database access.
Daily encrypted backups with point-in-time recovery. Stored in separate geographic regions.
24/7 infrastructure monitoring with automated alerting for security and performance issues.
Granular permissions system. Team members only see what they need to see.
Comprehensive logs of all access and changes. Available for compliance reviews.
Available for all accounts. Enforce 2FA for your entire team.
Automatic session timeouts and the ability to revoke sessions remotely.
We never use your data to train AI models. Your content stays yours.
AI only responds using your documentation. No hallucinations or made-up answers.
Every AI response can be traced back to specific sources in your knowledge base.
Full conversation visibility. Review, export, or delete any conversation.
All data is stored on Google Cloud Platform in US data centers. For EU customers with specific data residency requirements, contact us to discuss options.
No. We never use your knowledge base content, conversations, or any data to train AI models. Your data is only used to power your own Goldilocks instance.
Your data is accessible only to your team members with appropriate permissions. Goldilocks employees can access data only for support purposes when you explicitly request help, and all access is logged.
Deleted data is permanently removed from all active systems immediately. Backups containing deleted data are purged within 30 days.
We have a documented incident response plan. In the event of a security incident affecting your data, you would be notified within 72 hours with details and remediation steps.
Yes. Users on Growth and Scale plans can request a copy of our SOC2 Type 1 report by contacting support.
Yes. We provide a GDPR-compliant DPA for all customers. Contact support to execute one for your organization.
We use a minimal set of vetted subprocessors: Google Cloud Platform (infrastructure), OpenAI (AI processing), and Stripe (payments). A complete list is available on request.
Our security team is happy to discuss your requirements, answer questions about our practices, or provide documentation for your compliance needs.