Back to home

Security & Trust

Last updated: July 22, 2026

This page describes StaffGPT's security practices and architecture. It is intended to be accurate and non-confidential. Where a certification is not yet held, we say so plainly rather than imply otherwise.

Certifications and attestations

StaffGPT does not currently claim SOC 2, ISO 27001, or HIPAA certification. We describe our actual controls below and will update this page if and when formal attestations are completed. We do not represent that any deployment is HIPAA- or GDPR-compliant by default; compliance depends on your configuration, data, and contracts.

Hybrid and on-premises architecture

StaffGPT can run in our managed cloud, on customer-controlled machines, or in a hybrid model. In the local and hybrid models, a device-held private key remains on the customer's machine and is not transmitted to us, and machine pairing uses signed heartbeat communications to authenticate devices. On-premises and air-gapped deployments can keep processing within customer-controlled infrastructure.

Encryption

Data in transit is protected with TLS. Data at rest in our cloud is stored with our infrastructure providers, which provide encryption at rest for hosted databases and storage.

Access control and authentication

We use role-based access internally and authenticate users through our authentication provider. Multi-factor authentication for administrative users and enterprise SSO/SCIM are part of our roadmap for enterprise customers; availability is confirmed in the applicable order.

Infrastructure and subprocessors

We build on established infrastructure providers, including Supabase and Vercel. A current list is maintained in our Subprocessor List, and we assess providers for security and privacy suitability.

Vulnerability and incident response

We maintain an incident-response process and will notify affected customers of security incidents affecting their data without undue delay, consistent with our agreements. To report a vulnerability or security concern, contact security@staffgpt.net.

Customer responsibilities

Security is shared. Customers are responsible for managing their user access, protecting credentials and device keys, configuring deployments appropriately, and reviewing AI outputs before relying on them. Responsibilities for on-premises installations are set out in the applicable agreement.