Skip to content

Security

How we look after your team's work today. This page only lists things we actually do. If something you need isn't here, ask us at support@giveusaproject.com.

Last updated 24 September 2026

Your data, encrypted

  • On the way. Every connection to our site and app uses HTTPS (TLS). Browsers are told to always use HTTPS for our domain.
  • At rest. Your workspace lives in a Postgres database run by Neon, and uploaded files live in a private Vercel Blob store. Both providers encrypt stored data.
  • Keys and secrets. Passwords for connected tools, sign-in secrets and single sign-on settings are sealed with AES-256-GCM using our own master keys before we store them. They are never shown back in full.

AI with zero data retention

  • Zero data retention on every call. Archie and every other AI feature reach AI models only through the Vercel AI Gateway, and every request asks for zero data retention. The gateway only sends it to model providers that have agreed not to keep your prompts or the answers. If none is available, the request fails instead.
  • No training on your work. We never use your content, prompts or AI answers to train models, and every request also tells the gateway to use only providers that don't train on prompts.
  • Not in our logs. Our own logs never keep the text of prompts or AI answers. We record only what we need to run and bill the service, such as which model answered and how many words it used.
  • On every plan. This isn't an extra you pay for. It's how AI works in our product for everyone.

Who can see what

  • Your workspace, your rules. Every request checks that the person is a member of the workspace and allowed to see that project. Guests only see the projects they're invited to.
  • Archie has your access, not more. Archie works on behalf of the person asking, so it can never read or change anything that person can't.
  • Our team. Our staff see account details like workspace names and plans, not your content. Opening a workspace's content needs a written reason, lasts at most an hour, and is recorded in that workspace's history where its owners can see it.
  • Least privilege. Our GitHub App only asks to read. Files download through a check that you're allowed to see them. Add-ons run in a sandbox and only get the permissions you approve.

A record of changes

Each workspace keeps a history of important changes: sign-ins, people joining or leaving, role changes, connected tools, settings and staff access. Owners and admins can read it in Settings.

Signing in

  • No passwords to leak. You sign in with Google, GitHub or a one-time email link. We never store a password for you.
  • Single sign-on and provisioning. Single sign-on with SAML or OIDC (for example Okta, Microsoft Entra ID or Google Workspace) and admin controls come with our Business plan. SCIM provisioning comes with Enterprise. See our pricing page for details.

Where your data is

We store your data in the United States: the app runs on Vercel in its US East region and the database on Neon in US East. We don't offer other regions today.

The companies that help us run the service are listed on our Subprocessors page.

Found a problem?

If you think you've found a security issue, email support@giveusaproject.com with “Security” in the subject. Please don't share it publicly until we've fixed it. A person reads every message and we'll keep you posted.