Grayn logo Grayn
Security & Trust Center

We see your marketing data. Nobody else does.

Grayn handles sensitive performance data, creative assets, and customer segments. Security isn't a feature. It's the foundation.

S
Audited annually
G
GDPR
Compliant · DPA
O
OAuth 2.0
Read-only · Scoped
E
AES-256
Rest & transit
Principles

Six rules we build every decision around.

Principle 01

Read-only by default.

OAuth scopes are read-only. We never have write access unless you grant it for approved campaign actions — and even then, every write is gated by human approval.

Principle 02

Workspace isolation.

Every customer workspace is fully isolated at the database level. No data ever crosses customer boundaries. Not for training, not for benchmarks, not for "aggregate insights."

Principle 03

Encrypted, end to end.

AES-256 at rest. TLS 1.3 in transit. OAuth tokens use envelope encryption and rotate automatically. Keys managed in AWS KMS.

Principle 04

No training on your data.

Your campaigns, conversations, and documents only answer your team's questions. We never train foundation models on customer data. Your data improves your Grayn, not ours.

Principle 05

Every action logged.

Every question, data pull, and action is logged with user, timestamp, and reasoning. Exportable audit trail on Enterprise plans.

Principle 06

Right to delete.

Disconnect integrations and tokens revoke immediately. Delete your workspace and all data is purged within 30 days, including backups. No dark archives.

How data moves

From your ad account to your Slack.

01
OAuth connect
You grant read-only access via official OAuth from Google & Meta.
02
Encrypted fetch
Pulled over TLS 1.3, stored encrypted at rest in your isolated workspace.
03
Indexed privately
Vector embeddings in your tenant. Never shared across customers.
04
Answered in Slack
Queries route through your Slack App. No data leaves approved boundaries.
Campaign metadata & metrics
AWS us-east-1, encrypted at rest, isolated per workspace. Retained while subscription is active.
OAuth access tokens
Envelope encryption via AWS KMS. Token values never logged. Rotated on every refresh.
Uploaded brand documents
Encrypted S3. Indexed as private vector embeddings. Never shared across tenants.
Slack conversations
Messages route through Slack's infra. Grayn stores question history for memory, not Slack's full channel data.
Audit logs
All access events logged with user, IP, action. Exportable on Enterprise. Retained 7 years.
Subprocessors

The infrastructure we stand on.

Amazon Web Services

Compute, storage, KMS keys, database hosting.

US-EAST-1
Anthropic

Foundation model inference for natural language.

US · No training
OpenAI

Fallback inference & embeddings. Zero data retention.

US · No training
Slack

Messaging surface. Grayn operates as a Slack App.

US
Pinecone

Vector database for the Cortex memory. Isolated namespaces.

US · SOC 2
Datadog

Infrastructure monitoring. Metadata only, no customer data.

US

For complete subprocessor list, data flow diagrams, or to request our SOC 2 Type II report, DPA, or BAA, email security@grayn.ai.

Answers for your security team.

The eight questions we hear most from security reviews. More? Email security@grayn.ai.

No. We use foundation models routed through zero-data-retention endpoints. Your campaigns, creative, conversations, and documents only answer your team's questions.
OAuth with read-only scopes by default. We see what you authorized us to read — nothing more. For campaign launch (Scale/Enterprise), you grant scoped write permissions with spend caps and approval rules.
AWS US-EAST-1 (Northern Virginia). All data at rest encrypted with AES-256. All in transit encrypted with TLS 1.3. Each workspace is isolated at the database level.
Yes. Disconnect integrations any time and tokens revoke immediately. Delete your workspace and all data — including backups — is purged within 30 days.
SAML/SSO (Okta, Google Workspace) on Enterprise. Role-based access (Admin, Member, Viewer) on all plans, with granular permissions per integration.
Standard DPA available to all customers. BAA, custom MSA, and negotiated terms on Enterprise. Email security@grayn.ai.
SOC 2 Type II report available under NDA. Email security@grayn.ai — sent within 1 business day.
Customers notified within 24 hours of any confirmed incident affecting their workspace. Full incident response plan tested quarterly. Post-mortem shared publicly within 14 days.

We'll send the SOC 2 report.
You decide.

Most security reviews close in under a week. We move at your pace.

Request SOC 2 report Talk to security