← Back to Home

Trust and Security

Security Overview

Last updated: September 2026

This page is written for anyone evaluating PM Strategy Advisor on behalf of an organisation, including IT and security reviewers. It states plainly what is in place today, what is not, and how to reach us with questions. It complements, and does not replace, our Privacy Policy.

1. Security Posture

PM Strategy Advisor is an early-stage product operated by a single founder. We take a proportionate, honest approach to security: fix real gaps first, avoid overstating our maturity, and be direct with prospective customers about what a formal enterprise security review would still need to cover. We have not undergone a third-party penetration test or a SOC 2 audit. If your organisation requires either before approving a pilot, tell us and we will factor that into scope and timeline.

2. Data Hosting and Residency

We distinguish between where your data is stored and where it is processed:

  • Storage: account data, conversation history, Digital Twin facts, and journal entries are stored in Supabase, hosted in Frankfurt, Germany (EU). This data does not leave the EU at rest.
  • Processing: our application backend runs on Google Cloud Run in three regions (Europe, the United States, and Asia) to keep response times low for users in different time zones. A request may be processed by whichever region is closest to the user, but the underlying data it reads and writes remains in the EU-hosted database described above.
  • AI inference: messages sent to the advisor are routed through OpenRouter (US) to the underlying language model for real-time inference only. They are not retained by OpenRouter or the model provider for training.

A fully EU-only processing path (no request ever leaving the EU) is on our roadmap and can be discussed as part of an enterprise pilot. See Privacy Policy, Section 10 for the full list of sub-processors and international transfer safeguards.

3. Encryption

Data in transit is encrypted via TLS between your browser, our application, and our infrastructure providers. Data at rest is encrypted using the standard encryption-at-rest provided by Supabase and Google Cloud. We do not manage our own encryption keys separately from these providers today; customer-managed encryption keys are not currently offered.

4. Authentication and Access Control

User authentication is handled by Firebase Authentication (email and password, or Google Sign-In). Every request to our backend must carry a valid Firebase-issued token; requests without one are rejected before any data is touched.

Administrative functionality is restricted to a small, explicitly authorised set of accounts and is checked separately from normal user access. Single sign-on (SSO) for enterprise customers is not currently available; it is on our roadmap and can be prioritised for a committed pilot.

5. Your Conversations Are Not Used to Train AI Models

Conversation content is never used to train AI models, by us or by our inference provider. It is transmitted for real-time inference only. Full detail is in Privacy Policy, Section 4.

6. Sub-processors

The full, current list of sub-processors (who they are, what they do, and where they are based) is maintained in one place to avoid drift between pages: see Privacy Policy, Section 6. We will notify enterprise customers before adding a new sub-processor that would process their data.

7. Retention and Deletion

Account and conversation data are retained for as long as an account is active. On request, personal data is deleted within 90 days, except where retention is required by law. An organisation running a pilot can agree a shorter, specific deletion timeline for its own data as part of that engagement.

8. Reporting a Security Concern

If you believe you have found a security issue, or you are an IT or security reviewer with questions not answered on this page, contact [email protected]. We aim to acknowledge security reports within two business days.

9. Data Processing Agreement

A Data Processing Agreement (DPA) is available on request for organisations that need one in place before a pilot or subscription. It is provided as a starting point for discussion and is subject to review by your legal team and ours before signature. Request one at [email protected].

10. Roadmap

Items below are not yet in place. We list them so a reviewer does not have to ask, and so it is clear what "available on request" and "in progress" actually mean here:

  • Third-party penetration testing and a SOC 2 report
  • Single sign-on (SSO) for enterprise accounts
  • Fully EU-only processing path (no request leaving the EU)
  • Customer-managed encryption keys

If any of these is a hard requirement for your organisation, tell us early. We would rather scope a pilot around what is actually true today than promise a timeline we cannot commit to.