Trust Center
Where your data lives, how it's protected, and how we operate. The work you do with PolicySpeak is among the most sensitive material your organization produces — this is how we protect it.
Data storage
EU — Ireland (EEA)
Encryption
AES-256 at rest · TLS 1.2+ in transit
GDPR role
Data processor · DPA on request
Incident notice
Without undue delay
Last updated 7 June 2026. We update this page whenever our practices change.
If you're evaluating PolicySpeak and need to complete a security questionnaire, our Data Processing Addendum, AI Policy, and detailed sub-processor disclosure are available under NDA on request. For anything else, write to security@policyspeak.com — we respond within a few business days.
Where your data lives
Your account data and the content you create are stored in an EU-based managed database hosted in Ireland, inside the European Economic Area.
When you use an AI-powered feature, your content is processed in real time by our sub-processors to produce your output, under data-processing terms. We are working to put appropriate transfer safeguards, such as EU Standard Contractual Clauses, in place across our sub-processors, and we will update this page as those are completed. The full sub-processor list is available to customers under NDA on request.
You can request deletion of your organization's data at any time by writing to security@policyspeak.com. We are expanding self-service deletion and standardized retention windows as part of our 2026 roadmap.
Encryption
Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Encryption keys are managed by our infrastructure providers and rotated at least annually.
How we use AI
PolicySpeak is built on AI. We use multiple language models, embedding models, and supporting services across our intelligence pipeline. Our AI Policy describes how we build and operate these features, how we reduce the risk of incorrect output through source citation and verification, and how we approach the EU AI Act.
The complete sub-processor list and contractual terms are available to customers under NDA on request. Write to security@policyspeak.com for a sub-processor disclosure package — we respond within a few business days.
Who at PolicySpeak can see your content
Customer content is accessed only when needed to provide or troubleshoot the service, or when required by law. Access is role-based and recorded in an audit trail.
PolicySpeak is currently a small founding team. Access to customer content is restricted by role and revoked promptly on departure. As we hire, every new team member will complete security onboarding before access is granted.
Incidents
If we discover a security incident affecting your data, we will notify you without undue delay, with the facts as we know them, and follow up with a fuller report as our investigation progresses.
Audits and your rights
You may request a review of our security posture once per year via questionnaire, or by reviewing our DPA and sub-processor disclosure under NDA. Write to security@policyspeak.com to begin.
Certification roadmap
PolicySpeak is not currently certified against any external information-security standard. We operate the security controls that protect customer data: EU-hosted storage, encryption in transit and at rest, role-based access, audit logging, and a defined incident-response process. We are aligning these with the ISO 27001 and SOC 2 Trust Services Criteria as we work toward formal certification on our 2026–2027 roadmap, and we will publish certification status on this page as it is achieved.
EU data protection
We act as a data processor under GDPR. Our Data Processing Addendum is available to customers on request via security@policyspeak.com.
Documents
- AI PolicyHow we build and operate AI features.
- Acceptable Use PolicyThe rules governing use of the service.
- Privacy PolicyHow we handle personal data under GDPR.
- Data Processing AddendumAvailable to customers on request. Write to security@policyspeak.com.
- Sub-processor disclosure packageAvailable to customers under NDA on request. Write to security@policyspeak.com.
Talk to us about security
For security questions, questionnaires, evidence requests, our DPA, or sub-processor disclosure, write to our security team. We respond within a few business days.
security@policyspeak.com