Security

Protection is automatic, staff can't browse your content, and the only door in has your name on it.

What you build is yours

You build the panels. You recruit the personas. That's your IP — your knowledge of your users, compiled into something reusable that nobody else has.

Full export, any tier, any time, full fidelity. It leaves when you leave.

Protection is automatic

The moment your content reaches SQUAT — personas, interview transcripts, scenario text, evidence, screenshots — it's encrypted at the application layer under a key that belongs to your workspace alone, managed by the service in Cloud KMS. Nothing to set up, nothing to configure, no key file to lose.

Access is restricted by role: protected content comes back only to authorized seats in your workspace. SQUAT staff cannot browse your content. This is service-managed protection, not end-to-end encryption — the honest version of the promise is that no one browses your work, and the only path to any of it runs through you.

The only door has your name on it

If you ever ask support to look at something, that access is a grant you create: bound to the specific case, naming the exact fields support may see, expiring on its own, and fully audited. Support requests it; you approve it in your own client; you can revoke it at any time.

And there is deliberately no third-party access mechanism at all — no partner path, no integration path, no one else's door. Closed by design.

What isn't encrypted, and why

Statuses, failure classes, timings, version pins, and the numbers the ledger does arithmetic on are stored readable. That's not an oversight — it's how trend lines and regression flags can exist. What's protected is the content; what's readable is the bookkeeping.

Where the protection ends

Your AI platform sees what your agent shows you. SQUAT's protection covers your content inside SQUAT. It cannot cover the frontend you chose — Anthropic, OpenAI, or Google processes whatever gets displayed in your session. Check those settings too.

A grant can't be un-seen. Revoking support access prevents any later use, but it can't erase what was legitimately viewed during the authorized case. Grant the minimum scope you're comfortable with — the audit trail records every use either way.

What we keep

Only what running the service needs. Cancel and you get a read-only grace window with export reminders, then we delete your data — and we can certify that we did.

Last updated August 15, 2026