Skip to content
Goatfied

Legal

Trust & Security

How Goatfied protects your code, data, and privacy.

Data handling principles

  • You own your code. We do not claim ownership of anything you write or submit.
  • No training on your data (Teams/Enterprise). Teams and Enterprise plans include Privacy Mode, which prevents your prompts and code from being used for model training or improvement.
  • Minimal retention. Prompt and completion data is retained only as long as necessary for service delivery, debugging, and compliance. Teams can configure shorter retention windows.

Encryption

  • In transit: All traffic is encrypted via TLS 1.3. We enforce HTTPS everywhere and use HSTS preloading.
  • At rest: Databases and object storage use AES-256 encryption. Keys are managed via AWS KMS with automatic rotation.

Access controls

  • Least privilege: Internal access to production systems is granted on a need-to-know basis with role-based controls.
  • MFA required: All employees with production access must use hardware security keys or TOTP-based MFA.
  • Audit logging: Access to sensitive data is logged and reviewed. Logs are retained for at least 12 months.

Infrastructure security

  • Hosted on AWS with VPC isolation, security groups, and network ACLs.
  • DDoS protection via Cloudflare and AWS Shield.
  • Regular vulnerability scanning and patching. Critical patches applied within 24 hours.
  • Annual penetration tests by third-party firms. Reports available under NDA for Enterprise customers.

Compliance

  • SOC 2 Type II — In progress (Q3 2026 target).
  • GDPR — We process EU personal data in compliance with GDPR. Standard Contractual Clauses (2021/914) are available.
  • CCPA — California residents have rights under CCPA; see our Privacy Policy.
  • HIPAA — Not currently supported. Do not submit PHI.

Privacy Mode (Teams & Enterprise)

Privacy Mode is enabled by default on Teams Standard, Teams Premium, and Enterprise plans. When enabled:

  • Your prompts and completions are never used for training.
  • Retention is minimized to the shortest period required for service delivery.
  • Telemetry is limited to aggregate, non-identifying metrics.

Incident response

  • 24/7 on-call engineering rotation with defined escalation paths.
  • Security incidents are investigated and, where required, disclosed to affected customers within 72 hours.
  • Post-incident reviews are conducted and remediation tracked to closure.

Responsible disclosure

If you discover a security vulnerability, please report it to security@goatfied.com. We will acknowledge within 48 hours, triage promptly, and keep you informed of remediation progress. We do not pursue legal action against good-faith security researchers.

Questions

For security questionnaires, compliance documentation, or other inquiries, contact security@goatfied.com.

Next
Goatfied — The AI code editor