Your conversations and knowledge base deserve serious protection. Goldilocks is built with security at its core - not bolted on as an afterthought.
Security controls covering confidentiality, availability, and processing integrity, aligned with industry standards.
Built for global privacy requirements with data subject rights, consent management, and cross-border transfer protections.
California privacy compliance with data access, deletion, and opt-out capabilities.
All data transmitted over TLS (1.2 and above). No unencrypted connections accepted.
All stored data encrypted using AES-256. GCP-managed encryption for database and storage.
Complete tenant isolation at the database level. Your data is never mixed with other accounts.
When you delete data or close your account, it's permanently removed from active systems.
Hosted on Google Cloud Platform with enterprise-grade security, redundancy, and availability.
Private networking, firewall rules, and DDoS protection. No public database access.
Daily encrypted backups with point-in-time recovery.
24/7 infrastructure monitoring with automated alerting for security and performance issues.
Granular permissions system. Team members only see what they need to see.
Comprehensive logs of all access and changes.
Available for all accounts. Enforce 2FA for your entire team.
Automatic session timeouts. Removed team members lose access immediately.
We never use your data to train AI models. Your content stays yours.
AI responses are grounded in your documentation to minimise inaccuracies.
Every AI response can be traced back to specific sources in your knowledge base.
Full conversation visibility. Review, export, or delete any conversation.
All data is stored on Google Cloud Platform. Our primary production environment uses US regions (e.g. us-central1).
No. We never use your knowledge base content, conversations, or any data to train AI models. Your data is only used to power your own Goldilocks instance.
Your data is accessible only to your team members with appropriate permissions. Goldilocks employees can access data only for support purposes when you explicitly request help, and all access is logged.
Deleted data is permanently removed from active systems. Backup retention varies; automated database backups are retained for 7 days.
We have a documented incident response plan. In the event of a security incident affecting your data, affected customers are notified in accordance with applicable law (e.g. within 72 hours where required under GDPR).
We use Google Cloud Platform (infrastructure and OAuth), OpenAI (AI processing), Stripe (payments), and Mailgun (transactional email). See our Privacy Policy for the full list and locations.
Our security team is happy to answer questions about our practices.