Home › Security
Security & governanceEach subscriber runs on their own installation. Here is how it is built, who touches what, and where we are on the compliance road — stated plainly.
Each Client Ethos instance runs on its own dedicated database and application deployment. Your data never shares a database, a table, or a query with another customer's. There is no cross-tenant boundary to defend, because there is no shared tenancy at all.
Access rules are enforced at the database layer itself, not just in application code. Every table carries row-level security policies, so even a bug in the app cannot hand data to someone whose role does not permit it.
Admins, associates, sales reps, and virtual assistants each see only what their role allows. Client-facing users see their own engagement — nothing else. Deactivating a team member revokes access immediately, everywhere.
All traffic runs over TLS. Data is encrypted at rest on infrastructure that carries SOC 2 Type II attestation (Supabase on AWS). Payments are processed entirely by Stripe — card data never touches Client Ethos servers.
Every user sets their own inactivity sign-out window, with a hard one-hour ceiling enforced for all accounts. Password resets are handled with single-use, expiring links.
Every lead and deal carries its timeline: emails sent and received, meetings, status changes, proposals, and payments — attributable, timestamped, and reviewable by your admins.
We use a short list of processors, each for one job: Supabase (database, on AWS), Netlify (hosting), Postmark (email delivery), Stripe (payments), Deepgram (call transcription), and an LLM provider for drafting growth plans. No data broker ever touches your data, and we never sell or share it.
If an instance is compromised or a relationship ends, the entire instance can be locked in seconds — every user, every route — while data is exported or destroyed per your instructions.
We publish our posture honestly. Client Ethos is a young product built on audited infrastructure. We do not yet hold our own SOC 2 report, and we would rather tell you that plainly than decorate this page with badges. On the road ahead, in order: published Data Processing Agreement, SSO/SAML for enterprise plans, third-party penetration test, then a SOC 2 Type II audit of Client Ethos itself. Founding customers get a direct line to the people building this — ask us anything, including the hard questions.
Questions, security reports, or diligence requests: meeting@newdogai.com. We respond to responsible disclosure within two business days.
Diligence requests, security reports and responsible disclosure: meeting@newdogai.com. We respond within two business days.