Team0 · Security
What your Chief keeps
Letting an AI Chief build a living understanding from your mail, calendar and meetings is a real decision. So here is the specific version: what enters your World Model, what never does, who can see it, and what your Chief is permitted to do.
- Certification
- CASA Tier 2, independently assessed
- Sign-in
- Google — we hold no passwords
- The model
- Runs inside our own cloud account
What she keeps
Facts, not copies
Your World Model is made of individual conclusions, each with a source — not a warehouse of everything your Chief has read.
| From | She keeps | She does not store |
|---|---|---|
| Who people are, what was agreed, what you owe someone, dates that matter. | The messages themselves. There is no mailbox copy on our side. | |
| Calendar | Who you are meeting, when, and your history with them. | A standing copy of your calendar. |
| Meetings | The transcript and summary of meetings you record. | Anything from a meeting you did not ask her to join. |
| Documents | Text from files you upload, so she can search them. | Files you never gave her. |
| Connected tools | The key you supplied, encrypted and scoped to your account alone. | A copy of that tool’s data. |
Recorded meetings are the exception worth knowing about: those are stored word for word, because a summary you cannot check back against is worth very little. Nothing is recorded unless you send her to the meeting.
How it works
She works in the background, and on the moment
Two things are happening. In the background your Chief maintains the World Model — noticing what arrived, what changed, what conflicts and what is now overdue — so she does not start from zero when you next speak. In the moment, when you ask something or an event needs handling, she reads what that specific thing requires.
Either way, what she writes down is the conclusion rather than the source. This person works there, you promised them a reply, that was agreed on the 14th. Each one is separate, each shows where it came from, and each can be corrected or removed on its own. The messages themselves stay in your Google account, under the access you granted, which you can withdraw at any time.
Your side of it
You can see all of it, and undo all of it
- Every fact she holds is visible to you, one at a time, with the source it came from.
- Anything wrong can be corrected. Anything you would rather she forgot can be deleted immediately.
- A connected tool can be read-only, so she can see a system without being able to change anything in it.
- Disconnecting a tool cuts the access straight away — there is no lingering copy to go and find.
- If you close your account, personal information is deleted within 30 days — other than billing records, which we are required by law to keep.
Protection
How the data is held
Your data is kept apart from everyone else’s
Your people, facts, transcripts, actions and documents live in a database schema belonging to your account — the separation is in where the data is kept, not a filter the application has to remember to apply. Which account a request may touch is settled before anything runs, from your verified membership, and never from a value the caller supplies: if the same request carries two different answers to that question, it is refused rather than resolved.
Two separate checks, always
Proving who you are is not the same as proving whose data you may read, and we treat them as two questions rather than one. Anything unrecognised is refused rather than given the benefit of the doubt.
Nothing to steal at sign-in
You sign in with Google. Team0 holds no passwords — not hashed, not anywhere — so there is no password store to breach.
Encrypted throughout
Encrypted in transit on modern TLS only, and encrypted at rest with managed keys. The database is not reachable from the internet. Your connected-tool credentials are encrypted with a key specific to your account.
Independently assessed
We hold CASA Tier 2, assessed by an authorised external lab against the OWASP application security standard, and it is renewed annually rather than earned once.
If something goes wrong
What is recorded, and what you can check yourself
Everything above is about preventing a problem. This is about noticing one.
- Everything she says or sends on your behalf lands in one place — mail she sent, replies she gave a visitor, answers she gave in a meeting, messages to someone else’s agent. One switch stops her on any thread, mid-conversation.
- Infrastructure and administrative activity is logged separately from the application and retained independently of it.
- Your own Google audit log shows what our application accessed — independent of us, and not something you have to take on trust. You can withdraw our access from your side at any moment, without asking us first.
- If we confirm a breach affecting your data, you hear from us within 72 hours, by email to the account owner — including what we do not yet know at that point, rather than a polished account weeks later.
Who else sees it
The model runs in our own cloud account
This is usually the real question, so plainly: the model that reads your mail and writes your drafts runs inside our own AWS account, on the same infrastructure as everything else. The search index it relies on runs there too. Nothing we send anywhere is used to train a model.
- AWS — Hosting, storage and the AI model itself, under our agreement with them.
- Google — Only what your grant permits — and you can revoke it from your Google account at any time.
- OpenAI — Short passages of text, kept as a standby copy of the search index while we finish moving off it. Not what search actually runs on, and nothing is sent for training.
- Clerk — Sign-in and session handling.
- Transcription — Audio from the meetings you chose to record. Named for security reviewers on request.
- Payments — Billing details. Card numbers never reach Team0 at all.
What she won’t do
The limits are in what she can reach
An assistant that reads the open web and your inbox will eventually read something written to manipulate her. We do not assume we can spot every attempt. We assume some get through, and make sure it does not matter much when they do.
She cannot use a tool she was not given
What she is able to touch depends on where the conversation is happening. A public chat on your website reaches a deliberately small set of abilities. Persuading her to do something does not grant her the means.
Authority is explicit, not implied
You decide what your Chief may do, what always needs approval and what stays read-only. Drafting and thinking can happen quietly; consequential actions follow the authority you have set.
Another company’s agent sees a filtered version
When an outside agent talks to yours, what it can see is limited by the database query itself rather than by an instruction we hope she follows. Anything marked private or sensitive is excluded, anything not yet classified is treated as private, and an unrecognised caller falls to the narrowest setting rather than the widest.
Straight answers
Things we are asked, where the answer is no
We do not have SOC 2
We hold CASA Tier 2, which Google requires of any app handling restricted Google user data — assessed by an authorised external lab and renewed every year. We do not hold SOC 2 at this point. What CASA is.
We do not offer regional data residency
Everything runs in one region in the United States. If your data has to stay in a particular country, that is worth raising with us early — it is a real constraint and we would rather work through it with you at the start than discover it late.
We do not read your data ourselves
Access to production is limited and audited, and we do not browse customer content. If we ever need to look at something to fix a problem you have reported, we ask first.
For security reviewers
Our full posture record, control evidence and security policy go to reviewers on request. Penetration testing is welcome rather than merely tolerated — tell us the window and the scope and we will not treat it as an incident.
Reviews, questions and disclosure — hey@team0.ai