Security at Satcove

Your data is yours. Here is exactly how we protect it.

Privacy ControlsEncrypted TransportDeletion ControlsNo Password StoragePasswordless Auth

Infrastructure

  • Application hosting on Vercel and managed PostgreSQL/authentication on Supabase
  • Encrypted transport for browser, API, database, payment, and model-provider connections
  • Row-level database policies and service-role separation on protected data paths
  • Hosting and processing locations can vary by deployment and subprocessor; current details are provided during diligence

Authentication

  • Passwordless authentication via one-time codes (OTP) and magic links
  • No passwords stored — no password to leak
  • Google OAuth as alternative sign-in method
  • Session tokens with automatic rotation

Data privacy

  • Authenticated conversation history is stored so you can reopen it, subject to plan retention and deletion controls
  • Guest telemetry is content-free; authenticated operational analytics stores limited or anonymized content as described in the Privacy Policy
  • Queries needed for inference are sent to the selected AI providers after applicable Privacy Shield processing
  • Account deletion and history deletion are available; legal or billing records may follow separate required retention periods

API security

  • API keys are SHA-256 hashed before storage — we cannot see your key
  • Rate limiting on all endpoints (per-IP and per-key)
  • Content Security Policy (CSP), HSTS, X-Frame-Options, XSS protection headers
  • Stripe webhooks verified via cryptographic signatures

AI providers

  • Anthropic, OpenAI, Google, Mistral, Perplexity, and xAI can process prompts when their models are selected
  • A fallback can execute on a different provider; Satcove records requested and executed identities in consensus metadata
  • Provider terms, retention options, certifications, and processing locations are provider-specific and can change
  • Current subprocessor and transfer information is supplied during customer diligence rather than implied by a logo

Compliance

  • Privacy controls are designed to support access, correction, deletion, restriction, and objection requests where applicable
  • Account deletion covers account-linked product data; legally required transaction records may be retained separately
  • A DPA and current subprocessor details can be reviewed during a business pilot
  • No certification or regulatory status is claimed without the corresponding current evidence

Found a security issue?

Report it here

Satcove — A product by Abyssal Group