Every read of a board, canvas, file or meeting resolves the caller’s organization and department first, and queries are constrained to what that person can reach. The scoping is in the data access layer rather than in the interface, so a surface added later inherits it instead of having to remember it. Views that look across boards, like the Continuity Index and Contradiction Watch, only ever show boards you could already open.
An Executive sees across their organization’s departments. A member sees their own department, plus anything explicitly shared with them. Only a board’s owner can change it. Nothing leaves your organization unless someone in it publishes a board as a public link — which is deliberate, reversible, and shows a clean record rather than the workspace.
People join through an invite link that works once and expires after seven days, and only when a seat is free. We store only a scrambled form of each link, so a copy of our database could not be turned into working invites.
There is no back door for support to open a customer’s boards. Access requires consent you grant from your own account settings, lasts at most two hours once granted, and can be revoked at any time. Every request and every decision is written to our audit trail and to your organization’s own activity log. This is the control we would most want to see as a buyer, so it is the one we built first.
Text you write on a board, files you upload and meeting transcripts are sent to Anthropic and OpenAI to pick out decisions, risks and questions and how they connect. They process it for us under their business terms, which do not allow training on it, and we do not train models on it either.
Every item picked out shows the exact words it came from, and a quote is kept only if it really appears in what was written, so the record cannot put words in anyone’s mouth. Anything the assistant suggests on its own is labelled as a suggestion, not presented as something a person said.
Vercel, Supabase, Anthropic, OpenAI and Stripe. Four of those handle the content you write: Vercel hosts the app, Supabase stores it, and the two model providers run the extraction that builds the Continuity Index. The Privacy page sets out exactly which and why. Data is held in the United States.
We do not hold SOC 2, ISO 27001 or any other third-party attestation today, and we are not going to imply otherwise on a marketing page. We do not offer a contractual uptime guarantee on self-serve plans. We do not yet offer single sign-on (SAML) or SCIM provisioning, a choice of where data is stored, or a way to switch off the AI processing for one organization. If your procurement process needs any of these, talk to us before you start rather than after.
Found a vulnerability? Write to security@echo-logic.ai. Tell us what you found and how to reproduce it, give us reasonable time to fix it, and please do not access data that is not yours while proving the point. We will not pursue researchers who act in good faith.