Skip to content
01Security

Security, in specifics.

This page is not a promise with a badge on it. Every line below is quoted from the module pages themselves: what is isolated, who can reach it, how export and deletion work, and what our AI does and does not decide.

Organization isolation at the database level

Every record in every module is scoped to your organization and checked on each read and write. No path lets one organization query another's data.

Access starts at a seat

An active module entitlement plus a signed-in seat; some actions need explicit permissions beyond holding one.

Export carries the same boundary

Exports run on data your session can already see, under the same access rules as viewing.

Support access, disclosed

Signal*form staff can reach your organization's data for support, under the same model in every module. We name it rather than imply it cannot happen.

Encrypted in transit and at rest

And your data is never used to train models.

The honest limit

There is no self-serve organization-level deletion today, and support access exists as described above. We would rather you know both than discover either.

// __PART3__

Limits, in the modules' own words

Real limits, quoted verbatim from the validated module content. A limit you can check buys more trust than a vague claim.

Self-serve deletion

  • Spark*form: There is no self-serve organization-level deletion today.
  • Metric*form: There is no self-serve organization-level deletion today.
  • Flow*form:
  • Stack*form: There is no self-serve organization-level deletion today.
  • Skill*form: There is no dedicated flow to delete an employee's whole record inside Skill*form; removing someone from the roster happens through organization membership, and there is no self-serve organization-level deletion today.
  • Radar*form: There is no self-serve permanent deletion of a workspace or its research today.
  • Brain*form: There is no self-serve organization-level deletion today.
  • Pulse*form: There is no self-serve account deletion yet

Source coverage (Radar*form)

  • The Meta Ad Library is in the same free tier, but its own limit matters more than the other sources': Meta's public API returns commercial-ad data only where an ad's delivery reached the EU or UK; outside those markets, including for a Latin American or US brand, Radar*form skips the check rather than reporting a false empty result.
  • Reddit is not read: its free tier does not allow commercial use.
  • X is not read either: it currently has no usable free tier at all.

Module by module

Spark*form

Isolation
Every brief, client record, and persona is scoped to your organization at the database level, checked on every read and write, with no path for one organization to query another's data.
Access
Access requires an active Spark*form entitlement plus a signed-in seat; the public client portal returns only the single brief a token names, none of the client's other work. Signal*form staff can access any organization's Spark*form data for support, the same support model every module in the suite uses.
Export
PDF export runs on data your session already has permission to see, so it carries the exact same access boundary as viewing the brief.
Deletion
Deleting a client or a brief removes it, and the comments, versions, and generated assets attached to it, immediately. There is no self-serve organization-level deletion today.

Metric*form

Isolation
Every client, campaign, connection, alert, forecast, and insight is scoped to your organization at the database level, checked on every read and write, with no path for one organization to query another's data.
Access
Access requires an active Metric*form entitlement plus a signed-in seat; exporting data or generating a client portal link needs an explicit permission beyond just holding a seat, which organization owners and admins always have. A portal link is a random token in the URL, not a login: whoever holds it sees that one client's own campaigns and nothing about any other client in your organization, and revoking the link ends access immediately. Signal*form staff can access any organization's Metric*form data for support, the same support model every module in the suite uses.
Export
CSV export from the dashboard runs on data your session already has permission to see, gated by the same export permission that controls it in the app, so it carries the same access boundary as viewing the dashboard.
Deletion
Deleting a client removes it, and every campaign, connection, alert, forecast, insight, and portal link attached to it, immediately. There is no self-serve organization-level deletion today.

Flow*form

Isolation
Every project, task, time entry, budget, and client record is scoped to your organization at the database level, checked on every read and write, with no path for one organization to query another's data.
Access
Flow*form's permission model goes beyond a single admin-or-member split. Named presets, Owner, Finance, Account Director, Project Manager, Collaborator, and Contractor, control who sees cost rates and financial data specifically: Finance and Account Director see margins across every project, Project Manager sees delivery data but not cost rates, and Contractor is restricted to their own bookings, tasks, and time with financial data blocked outright, enforced at the database level rather than hidden in the interface. An expense can never be approved by the same person who submitted it, a rule enforced by a database trigger rather than left to a reviewer's judgment. Access still requires an active Flow*form entitlement plus a signed-in seat, and Signal*form staff can access any organization's Flow*form data for support, the same support model every module in the suite uses.
Export
PDF export and every AI-drafted document run on data your own session already has permission to see, so exporting never surfaces something the interface wouldn't already show you.
Deletion
Deleting a client, project, budget, or time entry soft-deletes it. An admin can see what was removed, by whom, and when, and restore it from a dedicated recovery view. There is no permanent, self-serve organization-level deletion today.

Stack*form

Isolation
Every tool, workflow, request, and comment is scoped to your organization at the database level, checked on every read and write, with no path for one organization to query another's data.
Access
Anyone with an active Stack*form entitlement and a signed-in seat in your organization sees every record, cost included, with no separate finance-only view; the public intake link only lets an anonymous visitor insert a new tool record, with no read access to anything already in the inventory. Signal*form staff can access any organization's Stack*form data for support, the same support model every module in the suite uses.
Export
CSV export and the PDF reports both run on data your session already has permission to see, so every export carries the exact same access boundary as viewing the dashboard.
Deletion
Deleting a tool removes it, and its comments, immediately. There is no self-serve organization-level deletion today.

Skill*form

Isolation
Every profile, service, HR record, document, and review is scoped to your organization at the database level, checked on every read and write, with no path for one organization to query another's.
Access
Anyone with an active Skill*form seat can see every colleague's directory profile, by design: that shared visibility is what the directory is for. Each person edits their own bio, skills, languages, and project history; only an org admin can set someone's manager or job level, enforced by a database rule rather than left to convention. Compensation carries the narrowest access in the product: an employee sees their own current pay, band, and full pay history; their manager sees only that report's current pay and band, never the history; beyond that, pay data is visible only to whoever an admin has explicitly granted access to. Signal*form staff supporting your organization use the same broad access model every module in the suite does for skills, time off, and documents; compensation is the one deliberate exception, with no staff-support access to pay data at all.
Export
HR documents and company-wide shared files download through a signed link that expires in a minute, carrying the same access boundary as viewing them. Resource-library templates download as branded files the same way. There is no bulk export of the directory, reviews, or compensation data today.
Deletion
Deleting a document, a shared file, a service, an announcement, a group, a goal, or a manager's private note removes it immediately. There is no dedicated flow to delete an employee's whole record inside Skill*form; removing someone from the roster happens through organization membership, and there is no self-serve organization-level deletion today.

Radar*form

Isolation
Every workspace, watchlist, session, source, and monitor is scoped to your organization at the database level, checked on every read and write, with no path for one organization to query another's.
Access
Access requires an active Radar*form entitlement plus a signed-in seat; a public portal link returns only the single report a token names, none of the workspace's other research. Signal*form staff can access any organization's Radar*form data for support, the same support model every module in the suite uses.
Export
PDF, PowerPoint, and CSV export run on data your session already has permission to see, so each one carries the same access boundary as viewing the report.
Deletion
Archiving a workspace removes it from your active list immediately and can be reversed; a document you upload can be deleted individually and immediately. There is no self-serve permanent deletion of a workspace or its research today.

Brain*form

Isolation
Every table starts with row level security switched on and no default access: a policy has to explicitly grant your organization's members a read or write, and that check runs on every single request, not once at login. There is no code path for one organization's session to query another organization's client data.
Access
Every record in a client's workspace defaults to internal and stays that way until someone explicitly flips it to client-visible, a change that first shows a confirm step naming exactly what is about to become visible, whether that's a profile field, a document, or a campaign. A client's own login reaches none of your organization's real tables: it reads only through a small set of curated portal views, one per record type, each built to leave out anything internal (a campaign's internal notes, a person's private notes) and to return only that one client's rows. Providers, provider grades, private notes, and the sharing log itself have no portal view at all, in any part of the product; there is no version of the client login that can reach them. When a client asks a question in their own portal, a separate external Ask function assembles the answer exclusively from those same curated views, so the internal side of the product is never loaded into that request in the first place. All of it is checked by an adversarial test suite that logs in as a client and asserts none of it is reachable, and that suite runs again before every release, not once at launch. Every time a record's visibility changes, a database trigger writes a permanent entry recording who changed what and when, and each client's workspace has a "Shared with client" screen listing exactly what's visible to them right now plus the full history of how it got that way. Signal*form staff can access any organization's Brain*form data for support, the same access model every module in the suite uses; that access sits outside the portal path entirely and does not widen what any client's own login can reach.
Export
A client-shareable report pulls from the exact same curated views the portal itself uses, so what a report shows and what the portal shows cannot drift into two different answers to "what does this client see." A separate internal report mode exists for your own team, can include internal content, and is labeled as internal on the page. There is no server-side PDF step: the report renders as print-ready HTML, and the PDF comes from the browser's own print function.
Deletion
Archiving a client hides it from your active list without deleting anything, and it already suspends that client's portal, since every portal view filters to active clients only. Deleting a client is a separate, explicit action that removes every record under it, including uploaded files in storage, immediately. There is no self-serve organization-level deletion today.

Pulse*form

Isolation
Every table Pulse*form writes to checks the reader's own ID against the row's owner on every read and write, and requires the organization's Pulse*form entitlement to be active on top of that. Unlike other modules in the suite, none of these tables carry a standing staff-access override: nobody at Signal*form can open another person's brief, task list, or draft queue through the product itself.
Access
Your manager doesn't get your brief, your colleagues can't search your mail, and nothing you read here reaches Brain*form or any other shared view in the suite. The Google connection itself is scoped narrowly: it can read mail and calendar, manage tasks, and send a message only after you approve a draft, and it specifically cannot permanently delete anything in your mailbox. The stored credential lives in a table your own signed-in account has no policy to read; only the scheduled jobs that run your sweep can reach it.
Export
There is no bulk export today. A brief is plain text, delivered in the app and to Telegram if you link it, so copying it out is a matter of copying text you can already read. There is no separate export path that reaches more than the brief already in front of you.
Deletion
Disconnecting an account deletes its stored credential immediately; it does not just mark the connection inactive. The raw nightly read behind each brief, and your chat history, are purged automatically after 30 days; the brief text itself, and your task and draft history, are not purged automatically today. There is no self-serve account deletion yet. If someone leaves the company, removing their seat ends their access to Pulse*form itself right away; the mailbox connection is separate, so disconnect it yourself before you go, or revoke it from inside your Google account's own settings, and the next scheduled sweep fails safely instead of continuing against an account that no longer grants it access.

What our AI does and does not decide

Each module states its own data statement, plus the line between what the AI decides and what stays with a person.

Spark*form

Brief, persona, and client content reaches Anthropic's and Google's commercial APIs only when you trigger a generation, never on a schedule or in the background. No code or configuration in this product asserts a training or retention policy for those calls; that determination sits with the provider's own account-level API terms, not with anything this product controls.

The AI decides

  • Expanding a short intake into a full structured draft
  • Naming which fields in a brief are vague, unsupported, or missing specificity, with a suggested rewrite for each
  • Drafting an audience persona from the brief's own context

The AI does not decide

  • Whether a brief is approved: that runs through your own approval chain
  • What ships to a client or a PM tool: every push to Asana, Monday, ClickUp, Notion, Slack, or Teams is a person clicking a button on an already-approved brief

Metric*form

A campaign's name, platform, objective, budget, status, and performance metrics reach Anthropic's commercial API only when you request an analysis or a forecast, never on a schedule or in the background. No code or configuration in this product asserts a training or retention policy for those calls; that determination sits with Anthropic's own account-level API terms, not with anything this product controls.

The AI decides

  • Writing a campaign's performance analysis: a score, named strengths and weaknesses, and prioritized recommendations with their expected impact, compared against your own stored industry benchmarks when they're set
  • Projecting spend, conversions, revenue, and ROAS for a chosen number of days ahead, from a campaign's trailing performance, falling back to a plain moving average if the AI call fails

The AI does not decide

  • Whether a budget changes, or a campaign pauses or resumes: every platform connection only reads that platform's API, and nothing in Metric*form writes back to Meta, Google Analytics, TikTok, LinkedIn, YouTube, Twitter/X, Snapchat, Pinterest, or Shopify
  • What a client sees or when: generating a report, exporting data, and sharing or revoking a portal link are a person clicking a button, never automatic

Flow*form

Project, time, and financial data reaches Anthropic's commercial API only when a chat turn runs or a scheduled agent job fires, never continuously or in the background. No code or configuration in this product asserts a training or retention policy for those calls; that determination sits with the provider's own account-level API terms, not with anything this product controls.

The AI decides

  • Answering a question about a project's health, deviation, margin, or capacity in chat, grounded in the same formulas the screens use, never a separate estimate
  • Flagging a project trending over budget, behind margin, or showing signs of undocumented scope creep, and drafting the internal explanation or a client-facing update
  • Drafting a proposal, a statement of work, or a monthly client narrative report from real project data, always saved as a draft

The AI does not decide

  • Who's assigned to a task or booked on a project: that's a person acting directly, or a rule an admin configured in the automation engine, never the AI itself choosing an assignment
  • What a project's budget or rate card is: those are set by a person, and every AI feature only ever reads them
  • Whether a client sees a report or a status update: a monthly narrative report is written as a draft and reaches the portal only once a person approves it

Stack*form

Stack*form does not call any AI model, and no tool, cost, or usage record in it is ever sent to an AI provider. Every number on the page, from a single tool's cost to the organization-wide monthly total, is computed directly from what your team entered.

The AI decides

    The AI does not decide

    • Every renewal bucket, monthly total, and category breakdown is date comparison and arithmetic on the numbers you entered, not a model's inference.
    • Approval routing follows the threshold and steps your organization configured; nothing is auto-approved, auto-rejected, or auto-flagged by a model.

    Skill*form

    Review notes, ratings, goal progress, a survey intent, or the numbers on an analytics screen reach Anthropic's commercial API only when you trigger one of those three actions, never on a schedule or in the background. No code or configuration in this product asserts a training or retention policy for those calls; that determination sits with Anthropic's own account-level API terms, not with anything this product controls.

    The AI decides

    • Drafting a performance review narrative from the ratings, notes, and goal progress a manager has already entered, without inventing a figure that isn't already in that material
    • Drafting a set of survey questions, in a mix of question types, from a one-sentence intent
    • Writing a short summary of whatever filtered analytics view is on screen, grounded only in the numbers on that screen

    The AI does not decide

    • Who fits a role or service: that score comes from a fixed formula weighing proficiency, whether a skill is required or preferred, and experience against what the service asks for, not a model's judgment
    • Whether a review narrative is final, whether a survey goes out, or who reports to whom: a manager edits and publishes the narrative, an admin reviews the questions before anything sends, and only an org admin can set a reporting line or level

    Radar*form

    Workspace, watchlist, and report content reaches Anthropic's commercial API whenever you run a report, a workflow, or a follow-up question, never on a schedule or in the background; Claude is required for the product to function at all. The visibility-sampling feature additionally sends a single unbranded prompt, the same question a real person would type, to whichever of ChatGPT, Gemini, or Perplexity your organization has configured its own key for. No code or configuration in this product asserts a training or retention policy for any of those calls; that determination sits with each provider's own account-level API terms, not with anything this product controls.

    The AI decides

    • Writing a report section's prose from the sources and the computed statistics it is handed, one model call per section
    • Which model answer counts as mentioning the tracked brand, for the visibility-sampling feature
    • How to organize a workflow's research into the sections its strategy framework defines

    The AI does not decide

    • Whether a citation is real: a claim whose cited source doesn't resolve to one actually provided is dropped from the report, not flagged as uncertain
    • What ships to a client: exporting a report, sharing a portal link, or sending a finding into another module is a person's action on a report that already exists

    Brain*form

    Client content used to answer a question or generate an insight reaches Anthropic's API only when someone in your organization triggers that request, never on a schedule or in the background; embedding a document for search runs inside Supabase's own infrastructure and never reaches Anthropic at all. The answer model requires the connected Anthropic account to run under a 30-day data retention setting; that is an account-level API term set by Anthropic, not a policy this product asserts or controls. On language: keyword search matches Spanish content at full strength, and every citation displays correctly regardless of language, but the model that ranks documents by meaning is English-only, so a Spanish document's similarity-based ranking is currently weaker than an equivalent English one.

    The AI decides

    • Which stored profile fields, people, campaigns, provider grades, and document passages are relevant to a question
    • How to phrase an answer from that content, with a citation attached to every claim it makes
    • What to surface when you ask for a generated insight, built only from what's actually in the client's record

    The AI does not decide

    • Whether anything becomes visible to a client: that's set explicitly by a person, through a confirm step, never inferred
    • What's true when the record is silent: Brain*form states plainly that it doesn't know rather than filling the gap with a guess

    Pulse*form

    Your email, calendar, task, and draft content reaches Anthropic's commercial API once a night during the scheduled sweep, and again whenever you chat or ask for a draft, never on any other schedule. No code or configuration in this product asserts a training or retention policy for those calls; that determination sits with Anthropic's own account-level API terms, not with anything this product controls.

    The AI decides

    • What counts as urgent tonight, weighing senders you've marked VIP more heavily
    • What goes into the morning brief and the weekly, monthly, and yearly retrospectives
    • The wording of a reply, when you ask it to draft one

    The AI does not decide

    • Whether a reply sends: a draft sits in the approval queue until you approve it, and a 60-second window after that still lets you undo it
    • Anything about another person's account: it reads only the inbox, calendar, and tasks you connected, and nothing it reads leaves Pulse*form for the rest of the suite