Security
How your briefs are protected, and how to tell us if you find something wrong.
This page is an unreviewed template
It is placeholder wording to make the page real, not legal advice, and it has not been reviewed by a lawyer. Replace it with counsel-approved text before you launch or collect any personal data.
Data protection
Traffic is served over TLS. Stored data is encrypted at rest by our hosting and database providers. Authentication is delegated to Google Firebase, so we never store passwords ourselves.
Access control
Access to production systems is limited to engineers who need it, protected by multi-factor authentication, and reviewed when someone changes role or leaves. Administrative actions are logged.
Your content
Briefs are scoped to your workspace. We do not use them to train shared models, and support staff do not read them unless you ask us to look at something specific.
Reporting a vulnerability
Write to security@seedand.com with steps to reproduce. We acknowledge within two business days and will keep you updated until it is resolved.
Please test only against your own account, do not access other people’s data, and give us reasonable time to fix an issue before publishing it. We will not pursue legal action against research conducted on those terms.
Related documents
See the privacy policy for what we collect, and the data processing addendum if you are a business customer.
Last updated 12 September 2026