Skip to content

Trust center · Reviewed September 30, 2026

Security and
data handling

What happens to your brand information, who can change it, and how published context reaches your tools.

Contact security
Under the hood

System
architecture

Encoder prepares your files. The Registry publishes and serves them. Your connected tools read the brand context.

Authoring

Encoder: authoring

Research, source extraction, review, and draft storage.

  • VercelApplication runtime
  • SupabaseDatabase + uploaded files
  • ClerkAccount sign-in
  • Model servicesHosted inference or your AI client
Publication

Registry: publishing

Signed publications, domain checks, and revision history.

  • Cloudflare WorkersRegistry request handling
  • Cloudflare storagePackages and publication state
  • Ed25519 signaturesPublication integrity
  • DNS verificationSeparate domain-control check
Use

Your AI tools: reading and editing

Read published context, or authorize a separate editing connection.

  • HTTPSPublic brand-file URLs
  • Read MCPRegistry context in AI clients
  • Authoring / Write MCPAuthenticated editing paths
  • Your AI providerYour account terms and settings

Supporting services: Stripe handles billing; Resend sends transactional emails. Public research can use Brave Search. Optional retrieval integrations are described below.

Data flow
What crosses the publishing boundary.
  1. Source material

    Guidelines, assets, links, and your answers.

    You choose the inputs
  2. Private drafts

    Extraction, research, and working BCP drafts.

    Encoder + processing providers
  3. Review & approve

    Check the actual files and asset links before publication.

    Authorized publisher
  4. Public Registry

    A signed package that people and AI tools can read.

    Public disclosure boundary

Only the approved package is intended for public publication. Source uploads are separate artifacts. Check file contents and asset URLs: public readers can keep copies.

Data storage and
publication

Publishing is a disclosure decision. A public Brand Context Protocol is readable by anyone who can fetch it, including AI tools.

Uploads and drafts

Original uploads are stored in Supabase Storage. Extracted text and session material are stored in the Encoder database. Server-side extraction processes source bytes; signed file URLs provide time-limited access. Owner checks are present on the inspected upload and extraction paths.

Application diagnostics can contain filenames, session identifiers, search queries, and error details. We do not claim that logs contain no customer information. Our privacy policy permits authorized staff review.

Published data

Review the files and asset links before publishing. Public Registry files are deliberately accessible. Publishing a BCP should not be confused with authorizing disclosure of every original source document.

Retention and deletion

For account retention and deletion requests, see our privacy policy or contact our privacy team. Public files may be retained by people and services that have downloaded them.

Read the privacy policy
Access and audit

Access control and
permissions

Private authoring, Registry publishing, and gated context use distinct permissions. Public BCP files remain available to everyone.

Workspace ownership

Each Encoder workspace has an owner. Active editors can propose changes; approvers can approve them. The owner controls publication and collaborator management. These roles apply to working material in Encoder.

Registry authoring

Publishing tools check customer identity and authoring role before changing a package or accessing its revision history. A prior retained publication can be restored as a new signed revision.

Section-level access grants

When private context is enabled, grants can limit a named user or installation to specific sections. Each served retrieval records the principal or installation, sections and content hashes, revision, time, and result. A failed audit write blocks that retrieval. Brand owners and designated admins can export these records.

Retrieval records describe the context Encoded served. Processing after delivery follows the connected AI client's terms and settings.

AI processing

AI processing: on our platform
or in your own tools

When you use Encoder

The production Encoder uses Anthropic’s commercial API for interview and BCP compilation requests. Source material and working context may be included in those requests. Anthropic says commercial API inputs and outputs are not used to train its models by default and are normally deleted within 30 days, subject to its published exceptions.

Research queries can go to Brave Search. Optional Zyte or Bright Data retrieval, when enabled, receives target URLs.

Anthropic training policy
Anthropic retention policy

When you use your AI client

Your agreement and settings with that provider govern processing in your client. Encoded remains responsible for information it receives through its tools and any processing those tools initiate.

Using your own client does not remove the need to review the connector's data access and publishing permissions.

Supplier assurance

Infrastructure and
subprocessors

These supplier-published reports and certifications cover the suppliers' systems. Each supplier sets the scope, report period, and access conditions.

Supabase

Database and source-file storage

SOC 2 Type II

Uploaded guidelines, extracted text, session records, and private drafts.

View supplier assurance

Vercel

Encoder and website hosting

SOC 2 Type II

Application requests, server processing, and application logs.

View supplier assurance

Cloudflare

Registry compute and storage

SOC 2 Type II · ISO 27001

Published BCP files, revision history, and Registry access requests.

View supplier assurance

Resend

Transactional email

SOC 2 Type II

Recipient addresses and the contents of service emails.

View supplier assurance

Public supplier sources checked September 29, 2026.

Common questions

Security FAQ

Does a signed BCP mean the brand is verified?

No. A signature allows you to check the integrity of a publication. Domain verification is a separate check. A claimed record is not, by itself, proof that the publisher represents the brand. Neither status certifies the truth of every claim in the files.

Are uploaded guidelines the same as published files?

No. Source documents, working drafts, and published BCP files are different artifacts. Review the contents and linked assets before approving a public publication. Do not put confidential information in a public BCP.

Can a public publication be recalled everywhere?

No. Removing a publication from our service cannot erase copies already downloaded by other people, search engines, or AI services. Public availability and deletion from systems we control are different things.

Does using my own AI keep everything outside Encoded?

Not necessarily. Your AI provider's terms and settings govern its processing. Information submitted to Encoded through a connector, including drafts and publishing requests, is also processed by Encoded. Tool-specific server work may involve additional processing.

Documents and contact

Report a security issue

For security reports, send the affected service, a description, and safe reproduction steps. Do not email passwords, access tokens, or customer records.

security@encodedbrands.ai

Assessment requests

Send your security questionnaire or procurement requirements to our security team. We can provide the available policies and discuss how Encoded handles your proposed use. We update this trust center as our infrastructure and practices evolve.