How Slashy protects your data

Your email, calendar, and memory are protected by audited controls, strong encryption, and strict data handling.

SOC 2 Type IIIndependently audited controls
CASA Tier 2Cloud application security assessment
Security testingIndependent reviews and testing
Strong encryptionAt rest and in transit

Data privacy

Do you use customer data to train AI models?

No. We do not use customer data to train our own models or any third party models. Your data will never be used to train another company's models, and our agreements require AI providers not to train on it.

Which AI providers do you use?

We use multiple AI providers to optimize for speed, accuracy, and cost. Our agreements require these providers not to retain or train on Slashy customer data:

  • OpenAI
  • Anthropic
  • Google
  • Groq
  • Fireworks AI
  • Novita AI
  • OpenRouter
  • Concentrate
  • Cartesia
  • LiveKit
  • Deepgram
  • Reducto

Infrastructure & security

Storage of customer data

All customer data is stored on encrypted filesystems in PostgreSQL databases, which run on AWS cloud servers in the United States. Here is exactly what we store:

Email and calendar data

Email metadata (subject lines, sender and recipient, timestamps, labels), email content (message bodies and attachments), and calendar events are stored in our PostgreSQL database. This data remains encrypted until you disconnect your Google account, at which point it is deleted within the timeline below. Access is tightly controlled and used only to provide the services you have chosen.

Agent conversations

We store your conversations with the Slashy AI agent to provide context and improve your experience. All conversations are encrypted.

Memories

The AI agent stores key facts it learns about you, your work patterns, and preferences to provide personalized assistance. All memories are encrypted and can be viewed or deleted at any time.

Usage logs

We maintain restricted logs for debugging and support. The information they contain is described in our Privacy Policy, and access is limited to team members who need it to provide support.

User preferences

Settings, custom labels, and UI preferences are stored to personalize your experience.

All data is encrypted in transit with TLS 1.2+ and at rest with 256 bit AES encryption.

What security measures do you have in place?

We use multiple layers of security controls:

  • Encryption: TLS 1.2+ for data in transit and 256 bit AES for data at rest
  • SOC 2 Type II: independently audited controls
  • Regular security testing: independent penetration testing and internal reviews
  • Infrastructure security: AWS and Supabase provide physical and network security with strict access controls
  • Secure authentication: OAuth 2.0 with Google, no password storage
  • Data isolation: logical separation of customer data with row level security policies

How does Slashy access my email and calendar?

Slashy connects to your Google account using OAuth 2.0, Google's secure authorization protocol. We only request the minimum permissions necessary to provide our service (read, send, and manage emails and calendar events). You can revoke access at any time through your Google Account settings. We never store your Google password or have access to accounts you haven't explicitly connected.

Google compliance: Slashy has completed a CASA (Cloud Application Security Assessment) Tier 2 assessment and follows the Google API Services User Data Policy.

What are your backup and disaster recovery capabilities?

We maintain backup and recovery procedures as part of our security program. Backup retention follows the timelines described in our Privacy Policy and contractual commitments. Enterprise customers can request current recovery documentation during security review.

What email security standards do you support?

Emails sent through Slashy inherit Gmail's SPF, DKIM, and DMARC protections. Since Slashy sends through your connected Gmail account, all outgoing messages automatically benefit from Google's email authentication and spoofing protection.

How do you protect against prompt injection?

Prompt injection is a technique where an attacker tries to override an AI system's instructions with malicious text. Slashy uses several safeguards to reduce that risk:

  • Input handling: user inputs and email content are sanitized before processing
  • Content boundaries: structured boundaries separate untrusted content from system instructions
  • Length limits: content limits reduce the ability of adversarial input to overwhelm the context

Compliance and auditing

Which independent assessments have you completed?

  • SOC 2 Type II: independent examination of our security controls
  • CASA Tier 2: Cloud Application Security Assessment

Can I get a copy of your penetration test results?

We conduct independent security testing and can share available documentation with prospective enterprise customers under NDA. Contact us at privacy@slashy.com to request the current materials.

How do you review your security controls?

Independent assessments, penetration testing, internal reviews, and automated scanning are used to evaluate our controls. Contact us for the dates and scope of the current reports.

How do you handle data breaches?

In the unlikely event of a data breach, we follow a strict incident response protocol:

  • Notification: customers notified without undue delay as required by applicable law and contract
  • Containment: immediate isolation of affected systems
  • Forensics: full forensic analysis to determine scope and root cause
  • Remediation: implementation of fixes and preventive measures
  • Cooperation: full cooperation with relevant authorities and regulators

Do you have a bug bounty program?

Yes. Slashy maintains a responsible disclosure program for vulnerabilities in our production applications and services. We review good faith reports and provide updates as they are triaged and remediated.

How to report

Email security@slashy.com with a clear description of the issue, reproduction steps, and the potential impact. Please do not publicly disclose the vulnerability until we have confirmed remediation.

Program rules

  • Only test against accounts you own. Do not access, modify, or exfiltrate data belonging to other users.
  • Stop testing and report immediately if you encounter any user data.
  • Do not perform denial of service, volumetric, or social engineering attacks.
  • Do not use automated scanners that generate significant traffic.
  • Give us a reasonable window to remediate before any public disclosure.

Out of scope

  • Missing security headers, cookie flags, or SPF/DMARC configuration without demonstrated impact
  • Self XSS, clickjacking on unauthenticated pages, or issues requiring physical access to a device
  • Rate limits, brute force, or account enumeration reports without material impact
  • Vulnerabilities in third party software or services we use but do not control
  • Denial of service, volumetric, or resource exhaustion attacks
  • Reports generated solely by automated scanners

Safe harbor

We will not pursue legal action against researchers who act in good faith, comply with this policy, and make a reasonable effort to avoid privacy violations, data destruction, or service disruption. If you are unsure whether specific testing is authorized, contact us at security@slashy.com before proceeding.

Your data control

What control do I have over my data?

You can request access to, export of, or deletion of personal data associated with your Slashy account:

  • Access or export: request a copy of the personal data we hold about you
  • Delete: submit a deletion request using the methods described below
  • Revoke access: disconnect your account instantly through Google Account settings or within Slashy
  • Manage preferences: update the controls available in Slashy settings

How do you handle privacy?

We follow established privacy principles in everything we build:

  • Purpose limitation: customer content is used to deliver requested features. Account and usage data may also be used to operate, secure, and improve the service as described in our Privacy Policy
  • Privacy by design: privacy considerations are built into every feature from the start
  • Transparency: we're clear about what data we collect and why
  • No selling of data: we never sell your personal data to third parties

To exercise any data rights, contact privacy@slashy.com. We respond to all requests within 30 days.

Do you offer a Data Processing Agreement (DPA)?

Yes. We provide a DPA for enterprise customers that outlines our data handling obligations. It's available on our DPA page or by contacting privacy@slashy.com.

Data management

Deletion of customer data

You can delete all your data at any time. Upon account disconnection or deletion request, we follow this timeline:

Immediate

Account access revoked, OAuth tokens invalidated, sync stopped

Within 24 hours

Hard delete from production systems (email and calendar data, AI memories, embeddings)

Within 7 days

Backups destroyed (up to 14 days during active incident investigations)

Data required by law (billing records) may be retained longer. Request immediate deletion at privacy@slashy.com.

Subprocessors

Slashy uses the following third party service providers that may process customer data. All subprocessors are bound by data processing agreements and are contractually obligated to maintain appropriate security measures.

Cloud infrastructure
ProviderPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure hostingUnited States
Supabase, Inc.Database and authenticationUnited States
VercelFrontend hosting and edge networkUnited States
LLM providers
ProviderPurposeLocation
OpenAIAI inference (GPT)United States
AnthropicAI inference (Claude)United States
GoogleAI inference (Gemini)United States
Open-source & inference infrastructure
ProviderPurposeLocation
GroqLow latency AI inferenceUnited States
Fireworks AIAI inferenceUnited States
Novita AIAI inferenceUnited States
OpenRouterAI inference routingUnited States
ConcentrateAI inference routingUnited States
Voice
ProviderPurposeLocation
CartesiaVoice AI (text-to-speech)United States
LiveKitReal-time voice and video infrastructureUnited States
DeepgramSpeech-to-textUnited States
Other services
ProviderPurposeLocation
StripePayment processingUnited States
PostHogProduct analyticsUnited States
SentryError monitoringUnited States
Temporal TechnologiesWorkflow orchestrationUnited States
ResendCustomer communicationsUnited States
CloudConvertFile conversionGermany
HTML/CSS to ImageImage renderingUnited States
PhotonAgent messaging integration (iMessage)United States
ComposioAgent tool integrations (Slack, Zoom)United States
ReductoDocument parsing (OCR)United States

Resources

Have security questions?

Our security team can help with compliance documentation, enterprise requirements, or questions about our practices.