Security
Built for companies that cannot afford a leak.
Concierca runs on your commercial data: pricing, stock, customers. Every layer is designed so that data stays yours, actions stay reviewable, and nothing leaves without a record.
What we promise, and can prove
Your data stays yours. Every action stays on the record.
No model training
We do not train models on your data. Inference is routed through OpenRouter, which does not use inputs or outputs for training, and only to providers whose policies say the same.
Data sovereignty and control
Your database lives in Zurich, encrypted at rest and in transit. Export any view as CSV or through the API. Retention windows delete runs, prompts and artifacts on your schedule.
Purpose-built security
Authentication with hashed passwords, breached-password screening, short-lived sessions and multi-factor login. Every decision, tool call and escalation is written to an audit log.
Isolation per company
Each company is its own workspace. No cross-company access. Departments, roles and per-item visibility decide who sees what, and no assistant can read what its owner cannot.
Human approval gates
Spending money, sending anything outbound, deleting data or passing a mission checkpoint pauses until a person approves, in the app or on Telegram. Nothing gated runs without a human.
Governed machine access
Claude, ChatGPT and other clients connect over MCP as a named user. Every call runs server-side under that user's role. Keys carry a per-tool allowlist. Secrets never travel the model channel.
Independently tested foundations
Built on providers with their own attestations: Supabase (SOC 2 Type 2, ISO 27001), Clerk (SOC 2 Type 2), Trigger.dev (SOC 2 Type II, third-party penetration tests), Composio (SOC 2 Type II, ISO 27001:2022). Their audits, stated as theirs.
Built on
Audited foundations. Named, not implied.
Every layer Concierca runs on carries its own audit. We name them, so you can check rather than trust.
Supabase
Postgres and storage in the Zurich region. AES-256 at rest, TLS in transit. SOC 2 Type 2, ISO 27001, DPA available.
Clerk
Authentication and sessions. SOC 2 Type 2. Hashed passwords, breached-password screening, multi-factor login. Hosted on US infrastructure under the Data Privacy Framework.
Trigger.dev
Background jobs and long-running work. SOC 2 Type II. AES-256 at rest, TLS in transit. Regular third-party penetration tests.
OpenRouter
Model routing with your own key. Does not train on inputs or outputs. Per-provider data policies and zero-data-retention controls.
Composio
Connection layer for third-party tools. Users authorise on a Composio-hosted link, so OAuth tokens never pass through our app or the model. Tokens are encrypted with AES-256-GCM and decrypted only at execution time. SOC 2 Type II and ISO 27001:2022, with production infrastructure in the United States.
FAQ
Clarity on the details.
How do we define customer data?
Everything you load into your workspace: sales, stock, purchase orders, customers, knowledge, memories, skills, and the prompts, outputs and artifacts produced for you. Login identity (name, e-mail, session) is handled by Clerk.
How is my data kept private and secure?
The database is encrypted at rest with AES-256 and in transit with TLS. Provider keys sit encrypted in a vault and are never shown in full again. Access is scoped by company, department, role and per-item visibility, and every action is logged.
Where is my data hosted and processed?
Your database and storage run in Supabase's Zurich region, and your commercial data stays there. Four services run on US infrastructure: Clerk for identity, Trigger.dev for background jobs, Composio for the connections to the tools you link, and OpenRouter for model requests. All four operate under data processing agreements and, where applicable, the EU-US Data Privacy Framework. We name every one of them rather than describe them as a category. When you connect a third-party tool yourself, that provider keeps its own copy of what passes through it, under its own terms.
How are access controls enforced?
Company isolation with no cross-company access. Roles: Admin, Member, Viewer. Department visibility: Open, Restricted, Private. A visibility picker on every knowledge item. Machine access over MCP runs server-side as the key owner with a per-tool allowlist. Gated actions require approval by a Company Admin.
How do you ensure no one trains on my data?
We do not train models on your data. Requests go through OpenRouter, which does not use inputs or outputs for training. Each model provider has its own policy; routing can refuse providers that train and enforce zero-data-retention endpoints.
How often are security audits performed?
Continuously, at the infrastructure level: Supabase annually for SOC 2 Type 2 and ISO 27001, Clerk for SOC 2 Type 2, Trigger.dev for SOC 2 Type II with regular independent penetration tests. Concierca inherits those controls and adds its own on top: isolation per company, human approval gates and an audit log on every action.

