Security & data handling

You're trusting us with real contracts - often commercially sensitive ones. Here's plainly what happens to your data, and how it's kept apart from everyone else's.

Where your data lives

Your contracts, extracted data, and account details are stored in a managed Postgres database hosted in London, UK. The application itself runs on Vercel. Nothing is stored on our own servers or laptops.

Your organization's data is isolated from every other organization's

Agreemnt is multi-tenant - many companies use the same system - so this matters. Every table in the database enforces row-level security: a rule, checked by the database itself on every single query, that a row can only be read or written by someone who's actually a member of the organization it belongs to. This isn't just a check in our application code that a bug could bypass - it's enforced at the database layer regardless of which part of the app is asking.

The original documents you upload follow the same rule: each file lives in a private storage location scoped to your organization and that specific contract, with matching access rules.

Encryption

Everything travels over HTTPS - between your browser and Agreemnt, and between Agreemnt and every service it talks to.

Where we store a secret on your behalf - the token that lets Agreemnt read your Google Drive, for example - it's encrypted (AES-256) before it ever touches the database, and only decrypted, server-side, at the moment it's actually needed to make a call to Google. It's never readable in plain form anywhere in storage.

How your contracts get read

However a contract reaches Agreemnt - uploaded directly, forwarded by email, or (if you choose to connect it) pulled in from Google Drive - the document's content is sent to Anthropic's Claude API to extract the structured details you see in the app: parties, value, dates, notice periods, and so on. That content isn't used to train Anthropic's models.

If you connect Google Drive, access is read-only - Agreemnt only ever lists and downloads files, and never modifies or deletes anything in your Drive. You can disconnect at any time from the settings page, which stops any further access immediately; contracts already imported stay put.

Who on your team can see what

Access is invite-only - someone has to be added to your organization by an existing owner or admin before they can see anything in it. Within an organization, everyone on the team can currently see every contract; assigning an owner to a contract is about accountability for follow-up, not about restricting who can view it.

Passwords

Authentication is handled by Supabase Auth, not by our own code - passwords are hashed and verified there, and Agreemnt never sees or stores one in readable form.

Where we're honest about not being finished yet

We haven't pursued a formal independent certification like SOC 2 yet - this page, and the practices behind it, are where we stand today as a small, early-stage team. As Agreemnt grows, formal certification is on our roadmap, not something we're claiming already.

Questions

If you've got a security question, or need to report a concern, get in touch and we'll respond directly - this isn't a form that disappears into a queue.