Skip to content
Goatfied

Trust

Security

How we protect your code, your prompts, and your team. Every claim on this page is one you can verify or ask us to evidence.

Encryption

TLS 1.2+ in transit with HSTS preload on every Goatfied domain. AES-256 at rest via AWS KMS. Enterprise customers can supply customer-managed KMS keys, so key revocation is under your control, not ours.

Isolation

Each tenant lives in a logically isolated namespace with per-tenant IAM scoping. Agent runs execute in ephemeral sandboxes with short-lived, repo-scoped credentials — never an org-wide token. Enterprise customers may run the inference plane entirely inside their own VPC.

Zero retention by default

On Free and Pro, prompts and completions are dropped once the request finishes. We do not train on your code. Audit logs contain metadata only — who, when, which model, how many tokens — never content.

Teams and Enterprise can enforce privacy mode organisation-wide so the setting cannot be disabled per seat.

Data residency

Requests are region-locked by default. US regions are the default; EU residency (eu-west-1) is available on request and is a configuration change, not a contract negotiation. We operate across 23 AWS regions.

Compliance

  • SOC 2 Type II — audit in progress, report expected Q3 2026. We will share the observation period and auditor name under NDA.
  • GDPR / UK GDPR / CCPA — our DPA is available for self-service execution.
  • HIPAA — BAA on request for Enterprise.
  • ISO 27001 — on the roadmap; not yet certified.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Sub-processors

Every third party that may process customer data is published at goatfied.com/docs/subprocessors. We give notice before adding a new one.

Disclosure

Report a vulnerability to security@goatfied.com. PGP key available on request. We acknowledge within 24 hours and will not pursue legal action against good-faith research that respects user privacy and avoids service degradation.

Status

Live availability and incident history: status.goatfied.com.

Questions

Security reviews, questionnaires and architecture calls: enterprise@goatfied.com.

Security · Goatfied