Trust
Security
A brand workspace holds your identity, product data and unreleased campaigns. These are the practices we follow to keep it private to your team.
Last updated · 12 August 2026
Access control
Every workspace, asset and generation record is scoped to its owner and team through row-level security. Team members only see workspaces they were invited to, and their role determines whether they can generate, spend credits or manage members.
Encryption
All traffic between your browser, our servers and AI providers is encrypted in transit with TLS. Stored files and database records sit on encrypted managed infrastructure.
Secrets handling
API keys and provider credentials live in server-side secret storage. They are never exposed to the browser and never returned by an API response.
Auditability
Credit movements, admin adjustments, generation jobs and team changes are recorded with a timestamp, actor and reason so you can reconstruct what happened in your account.
Rate limiting and abuse protection
Generation endpoints are rate limited per account on a rolling window, with monthly spend caps available for teams so a single member cannot exhaust a shared balance.
Responsible disclosure
Found a vulnerability? Email security@softsasi.com with steps to reproduce. Please give us reasonable time to fix the issue before disclosing it publicly, and avoid accessing data that is not your own.
Questions about this policy? Email hello@softsasi.com and our team will respond within two business days.
