Security
How we handle your data.
What is true today, stated plainly. We do not hold SOC 2, HIPAA or other certifications, and we will tell you so on the call.
NDA firstWe sign an NDA before we look at your data or systems.
You own what we buildWorkflows, code and agents are yours. No lock-in on agents.
Read-only by defaultWhere a tool only needs to read, it gets read-only access. Warm Outreach, for example, never sends an email.
Where data is storedYour data stays in the systems you already use. Anything we host for you runs on infrastructure we name in writing, with its region, before we start.
Who has accessNamed Esipick engineers only, with the least access the job needs. We remove our access when the work ends or when you ask.
Retention and deletionWe keep project data only as long as the work needs it. On written request we delete it and confirm in writing.