Skip to main content
Seedand

Security

How your briefs are protected, and how to tell us if you find something wrong.

This page is an unreviewed template

It is placeholder wording to make the page real, not legal advice, and it has not been reviewed by a lawyer. Replace it with counsel-approved text before you launch or collect any personal data.

Data protection

Traffic is served over TLS. Stored data is encrypted at rest by our hosting and database providers. Authentication is delegated to Google Firebase, so we never store passwords ourselves.

Access control

Access to production systems is limited to engineers who need it, protected by multi-factor authentication, and reviewed when someone changes role or leaves. Administrative actions are logged.

Your content

Briefs are scoped to your workspace. We do not use them to train shared models, and support staff do not read them unless you ask us to look at something specific.

Reporting a vulnerability

Write to security@seedand.com with steps to reproduce. We acknowledge within two business days and will keep you updated until it is resolved.

Please test only against your own account, do not access other people’s data, and give us reasonable time to fix an issue before publishing it. We will not pursue legal action against research conducted on those terms.

Related documents

See the privacy policy for what we collect, and the data processing addendum if you are a business customer.

Last updated 12 September 2026