SuperEmber Trust Center

Principles behind our “Trust me, Bro” security.

You don’t have to trust us. Just know that the controls are operating, the evidence exists, and the only thing missing is the expensive independent audit and framed paper.

Things we can actually prove

Less “trust us.” More controls.

Each promise maps to a named control below. The public summary stays readable while detailed evidence remains access-controlled.

AI-01

Your work is not training data

SuperEmber does not use private customer content to train public models.

AI-02

Zero-retention AI routing

Eligible model requests are restricted to approved providers and ZDR endpoints.

PR-01

Consent-first analytics

Browser analytics stays off until consent and excludes prompts, messages, and names.

AC-01

Tenant-scoped access

Workspace data and product operations are resolved inside explicit tenant boundaries.

Public control ledger

The receipts.

A customer-readable index of operating controls. No sensitive implementation details.

IDAreaPublic control summaryStatus
AI-01Model data handlingPrivate customer content is not used for SuperEmber model training.Operating
AI-02Provider routingApproved provider allowlist and ZDR endpoint restriction.Operating
PR-01Browser analyticsExplicit consent; autocapture and session replay disabled.Operating
AC-01Workspace accessTenant-scoped authorization and pseudonymous analytics identity.Operating
GV-01ISO 27001 control foundationOperating ISMS controls and evidence for ISO/IEC 27001; independent certification not yet obtained.Operating
GV-02Supplier assuranceDPA, region, transfer, deletion, and incident evidence register.Operating
GV-03SOC 2 control foundationOperating controls and evidence prepared for a SOC 2 Type I examination; no independent SOC 2 report yet.Operating

Compliance profile

Controls first. Expensive paper second.

The foundation is built and operating. What is missing is independent confirmation: the accredited audit, CPA report, and framed paper.

GDPR

Privacy is not an optional add-on

SuperEmber is based in the EU. GDPR is a legal obligation, not an aspiration or a paid badge. Our DPA, privacy operations, retention, supplier, transfer, and rights processes form part of the operating foundation.

Required

ISO 27001

Controls before certificate

The ISMS foundation, including scope, owners, risk method, policies, evidence, reviews, and corrective actions, is operating. SuperEmber is not currently ISO 27001 certified; the accredited certification audit is the missing step.

Missing money

SOC 2

Controls before CPA report

The same control and evidence foundation supports SOC 2 Type I attestation. No SOC 2 report is currently available; independent examination by a licensed CPA firm is the remaining step.

Missing money

How data moves

A boundary at every handoff.

The detailed architecture remains private. This public path shows where responsibility changes.

01

Your workspace

Messages, files, and instructions you choose to share.

02

SuperEmber

Tenant-scoped orchestration and policy enforcement.

03

Approved AI

ZDR-restricted processing through reviewed providers.

04

Your destination

Results return to the channel or service you requested.

Material providers

Who else touches the data.

Provider purpose and transfer information lives in the public register. Contractual evidence remains controlled.

VercelNeonClerkOpenRouterUpstashPostHogComposio

Need additional assurance materials? Contact privacy@superember.ai.