Trust

How we protect customer data, our compliance posture, and the third parties that help us operate the platform.

Security

  • TLS 1.2+ in transit; AES-256 at rest (Google-managed keys).
  • Tenant isolation enforced by Postgres row-level filters and the shared tenant-route helper.
  • Secrets stored in GCP Secret Manager and injected into Cloud Run at deploy time.
  • Hybrid auth: Firebase Auth + NextAuth sessions over Cloud SQL source of truth.
  • Distributed rate limits via Upstash Redis (fail-open).

Compliance

  • SOC 2 Type II — in progress, evidence collected via Drata. Letter of engagement available on request.
  • GDPR — DPA + SCCs available; user export and delete implemented.
  • CCPA / CPRA — in production.

Privacy

See our privacy notice for the full record of data we collect, retention windows, and user rights.

Data Processing Addendum

Our DPA is available on request — email legal@neww.ai.

Subprocessors

VendorPurposeRegion
Google Cloud PlatformCompute, Cloud SQL, GCS, Cloud TasksUS
AnthropicLLM inference (Claude)US
GroqFast LLM inference (Llama)US
OpenAIBackup LLM + embeddingsUS
StripeBilling and paymentsUS / EU
PostHogProduct analyticsUS
UpstashDistributed cache and rate limitsUS / EU
DrataCompliance evidence collection (SOC 2)US

Data residency

Data classRegionNotes
User profiles, workspacesus-central1 (Cloud SQL)Replicated within region.
Generated artifactsus-central1 (GCS)Encrypted at rest with Google-managed keys.
Chat ephemeralus-central1 (Firestore)TTL-bounded; not used as source of truth.
Cache + locksUpstash global edgeNon-PII keys only.

Incident response

Live platform health is published at /status. Customer-impacting incidents are recorded there with a timestamped update log; security incidents that affect customer data are also notified per contract terms.