Encoder: authoring
Research, source extraction, review, and draft storage.
- VercelApplication runtime
- SupabaseDatabase + uploaded files
- ClerkAccount sign-in
- Model servicesHosted inference or your AI client
Trust center · Reviewed September 30, 2026
What happens to your brand information, who can change it, and how published context reaches your tools.
Contact securityEncoder prepares your files. The Registry publishes and serves them. Your connected tools read the brand context.
Research, source extraction, review, and draft storage.
Signed publications, domain checks, and revision history.
Read published context, or authorize a separate editing connection.
Supporting services: Stripe handles billing; Resend sends transactional emails. Public research can use Brave Search. Optional retrieval integrations are described below.
Guidelines, assets, links, and your answers.
You choose the inputsExtraction, research, and working BCP drafts.
Encoder + processing providersCheck the actual files and asset links before publication.
Authorized publisherA signed package that people and AI tools can read.
Public disclosure boundaryOnly the approved package is intended for public publication. Source uploads are separate artifacts. Check file contents and asset URLs: public readers can keep copies.
Publishing is a disclosure decision. A public Brand Context Protocol is readable by anyone who can fetch it, including AI tools.
Original uploads are stored in Supabase Storage. Extracted text and session material are stored in the Encoder database. Server-side extraction processes source bytes; signed file URLs provide time-limited access. Owner checks are present on the inspected upload and extraction paths.
Application diagnostics can contain filenames, session identifiers, search queries, and error details. We do not claim that logs contain no customer information. Our privacy policy permits authorized staff review.
Review the files and asset links before publishing. Public Registry files are deliberately accessible. Publishing a BCP should not be confused with authorizing disclosure of every original source document.
For account retention and deletion requests, see our privacy policy or contact our privacy team. Public files may be retained by people and services that have downloaded them.
Read the privacy policyPrivate authoring, Registry publishing, and gated context use distinct permissions. Public BCP files remain available to everyone.
Each Encoder workspace has an owner. Active editors can propose changes; approvers can approve them. The owner controls publication and collaborator management. These roles apply to working material in Encoder.
Publishing tools check customer identity and authoring role before changing a package or accessing its revision history. A prior retained publication can be restored as a new signed revision.
When private context is enabled, grants can limit a named user or installation to specific sections. Each served retrieval records the principal or installation, sections and content hashes, revision, time, and result. A failed audit write blocks that retrieval. Brand owners and designated admins can export these records.
Retrieval records describe the context Encoded served. Processing after delivery follows the connected AI client's terms and settings.
The production Encoder uses Anthropic’s commercial API for interview and BCP compilation requests. Source material and working context may be included in those requests. Anthropic says commercial API inputs and outputs are not used to train its models by default and are normally deleted within 30 days, subject to its published exceptions.
Research queries can go to Brave Search. Optional Zyte or Bright Data retrieval, when enabled, receives target URLs.
Anthropic training policyYour agreement and settings with that provider govern processing in your client. Encoded remains responsible for information it receives through its tools and any processing those tools initiate.
Using your own client does not remove the need to review the connector's data access and publishing permissions.
These supplier-published reports and certifications cover the suppliers' systems. Each supplier sets the scope, report period, and access conditions.
Database and source-file storage
SOC 2 Type IIUploaded guidelines, extracted text, session records, and private drafts.
View supplier assuranceEncoder and website hosting
SOC 2 Type IIApplication requests, server processing, and application logs.
View supplier assuranceRegistry compute and storage
SOC 2 Type II · ISO 27001Published BCP files, revision history, and Registry access requests.
View supplier assuranceAccount authentication
SOC 2 Type IIAccount identity and sign-in information.
View supplier assurancePayment processing
PCI DSS Level 1 service providerBilling and payment information.
View supplier assuranceTransactional email
SOC 2 Type IIRecipient addresses and the contents of service emails.
View supplier assurancePublic supplier sources checked September 29, 2026.
No. A signature allows you to check the integrity of a publication. Domain verification is a separate check. A claimed record is not, by itself, proof that the publisher represents the brand. Neither status certifies the truth of every claim in the files.
No. Source documents, working drafts, and published BCP files are different artifacts. Review the contents and linked assets before approving a public publication. Do not put confidential information in a public BCP.
No. Removing a publication from our service cannot erase copies already downloaded by other people, search engines, or AI services. Public availability and deletion from systems we control are different things.
Not necessarily. Your AI provider's terms and settings govern its processing. Information submitted to Encoded through a connector, including drafts and publishing requests, is also processed by Encoded. Tool-specific server work may involve additional processing.
For security reports, send the affected service, a description, and safe reproduction steps. Do not email passwords, access tokens, or customer records.
security@encodedbrands.aiSend your security questionnaire or procurement requirements to our security team. We can provide the available policies and discuss how Encoded handles your proposed use. We update this trust center as our infrastructure and practices evolve.