Trust and Security
Last updated: September 2026
This page is written for anyone evaluating PM Strategy Advisor on behalf of an organisation, including IT and security reviewers. It states plainly what is in place today, what is not, and how to reach us with questions. It complements, and does not replace, our Privacy Policy.
PM Strategy Advisor is an early-stage product operated by a single founder. We take a proportionate, honest approach to security: fix real gaps first, avoid overstating our maturity, and be direct with prospective customers about what a formal enterprise security review would still need to cover. We have not undergone a third-party penetration test or a SOC 2 audit. If your organisation requires either before approving a pilot, tell us and we will factor that into scope and timeline.
We distinguish between where your data is stored and where it is processed:
A fully EU-only processing path (no request ever leaving the EU) is on our roadmap and can be discussed as part of an enterprise pilot. See Privacy Policy, Section 10 for the full list of sub-processors and international transfer safeguards.
Data in transit is encrypted via TLS between your browser, our application, and our infrastructure providers. Data at rest is encrypted using the standard encryption-at-rest provided by Supabase and Google Cloud. We do not manage our own encryption keys separately from these providers today; customer-managed encryption keys are not currently offered.
User authentication is handled by Firebase Authentication (email and password, or Google Sign-In). Every request to our backend must carry a valid Firebase-issued token; requests without one are rejected before any data is touched.
Administrative functionality is restricted to a small, explicitly authorised set of accounts and is checked separately from normal user access. Single sign-on (SSO) for enterprise customers is not currently available; it is on our roadmap and can be prioritised for a committed pilot.
Conversation content is never used to train AI models, by us or by our inference provider. It is transmitted for real-time inference only. Full detail is in Privacy Policy, Section 4.
The full, current list of sub-processors (who they are, what they do, and where they are based) is maintained in one place to avoid drift between pages: see Privacy Policy, Section 6. We will notify enterprise customers before adding a new sub-processor that would process their data.
Account and conversation data are retained for as long as an account is active. On request, personal data is deleted within 90 days, except where retention is required by law. An organisation running a pilot can agree a shorter, specific deletion timeline for its own data as part of that engagement.
If you believe you have found a security issue, or you are an IT or security reviewer with questions not answered on this page, contact [email protected]. We aim to acknowledge security reports within two business days.
A Data Processing Agreement (DPA) is available on request for organisations that need one in place before a pilot or subscription. It is provided as a starting point for discussion and is subject to review by your legal team and ours before signature. Request one at [email protected].
Items below are not yet in place. We list them so a reviewer does not have to ask, and so it is clear what "available on request" and "in progress" actually mean here:
If any of these is a hard requirement for your organisation, tell us early. We would rather scope a pilot around what is actually true today than promise a timeline we cannot commit to.