Legal
Trust & Security
How Goatfied protects your code, data, and privacy.
Data handling principles
- You own your code. We do not claim ownership of anything you write or submit.
- No training on your data (Teams/Enterprise). Teams and Enterprise plans include Privacy Mode, which prevents your prompts and code from being used for model training or improvement.
- Minimal retention. Prompt and completion data is retained only as long as necessary for service delivery, debugging, and compliance. Teams can configure shorter retention windows.
Encryption
- In transit: All traffic is encrypted via TLS 1.3. We enforce HTTPS everywhere and use HSTS preloading.
- At rest: Databases and object storage use AES-256 encryption. Keys are managed via AWS KMS with automatic rotation.
Access controls
- Least privilege: Internal access to production systems is granted on a need-to-know basis with role-based controls.
- MFA required: All employees with production access must use hardware security keys or TOTP-based MFA.
- Audit logging: Access to sensitive data is logged and reviewed. Logs are retained for at least 12 months.
Infrastructure security
- Hosted on AWS with VPC isolation, security groups, and network ACLs.
- DDoS protection via Cloudflare and AWS Shield.
- Regular vulnerability scanning and patching. Critical patches applied within 24 hours.
- Annual penetration tests by third-party firms. Reports available under NDA for Enterprise customers.
Compliance
- SOC 2 Type II — In progress (Q3 2026 target).
- GDPR — We process EU personal data in compliance with GDPR. Standard Contractual Clauses (2021/914) are available.
- CCPA — California residents have rights under CCPA; see our Privacy Policy.
- HIPAA — Not currently supported. Do not submit PHI.
Privacy Mode (Teams & Enterprise)
Privacy Mode is enabled by default on Teams Standard, Teams Premium, and Enterprise plans. When enabled:
- Your prompts and completions are never used for training.
- Retention is minimized to the shortest period required for service delivery.
- Telemetry is limited to aggregate, non-identifying metrics.
Incident response
- 24/7 on-call engineering rotation with defined escalation paths.
- Security incidents are investigated and, where required, disclosed to affected customers within 72 hours.
- Post-incident reviews are conducted and remediation tracked to closure.
Responsible disclosure
If you discover a security vulnerability, please report it to security@goatfied.com. We will acknowledge within 48 hours, triage promptly, and keep you informed of remediation progress. We do not pursue legal action against good-faith security researchers.
Questions
For security questionnaires, compliance documentation, or other inquiries, contact security@goatfied.com.
Next