Trust

Security

A brand workspace holds your identity, product data and unreleased campaigns. These are the practices we follow to keep it private to your team.

Last updated · 12 August 2026

Access control

Every workspace, asset and generation record is scoped to its owner and team through row-level security. Team members only see workspaces they were invited to, and their role determines whether they can generate, spend credits or manage members.

Encryption

All traffic between your browser, our servers and AI providers is encrypted in transit with TLS. Stored files and database records sit on encrypted managed infrastructure.

Secrets handling

API keys and provider credentials live in server-side secret storage. They are never exposed to the browser and never returned by an API response.

Auditability

Credit movements, admin adjustments, generation jobs and team changes are recorded with a timestamp, actor and reason so you can reconstruct what happened in your account.

Rate limiting and abuse protection

Generation endpoints are rate limited per account on a rolling window, with monthly spend caps available for teams so a single member cannot exhaust a shared balance.

Responsible disclosure

Found a vulnerability? Email security@softsasi.com with steps to reproduce. Please give us reasonable time to fix the issue before disclosing it publicly, and avoid accessing data that is not your own.

Questions about this policy? Email hello@softsasi.com and our team will respond within two business days.