Trust Center
Last updated: July 23, 2026
Our approach to trust
Aldwin plans, generates, and executes marketing work across the systems you connect, which means we handle your marketing data and act in your connected accounts on your behalf. We treat that as a responsibility to be earned, not assumed: security, tenant isolation, and human approval are built into the architecture rather than added on top.
This page describes the controls in force today and is honest about what is still on our roadmap. For the binding commitments, see our Privacy Policy, Terms of Service, Sub-processor list, and Data Processing Addendum.
Data isolation
- Every workspace's data is isolated at the database level. All workspace-scoped tables enforce row-level security with a per-workspace isolation policy, and the production database connects under a role that cannot bypass those policies.
- Application-level authorization is enforced in addition to database isolation, so one customer's workspace cannot read or write another's. The boundary is enforced by the database itself, not only by application code.
Encryption
- In transit: TLS 1.2 or later on the public application and production API, with TLS 1.3 supported and legacy protocols (TLS 1.0 and 1.1) rejected.
- Integration credentials: connected-platform access tokens are encrypted with AES-256-GCM using per-workspace derived keys, so each workspace's credentials are protected under a distinct key.
- Payments: card details are entered on Stripe-hosted checkout; Aldwin never stores or has access to full card numbers.
- Managed database, cache, object-storage, and backup encryption at rest follows each infrastructure provider's current attestations; we do not claim a single universal at-rest scheme of our own.
Access control
- Multi-factor authentication is available to all users and is required, with recent-authentication re-verification, for Aldwin-internal administrative access.
- Access to production follows least-privilege principles, and authenticated sessions are subject to a maximum token age after which re-authentication is required.
- Authentication and session management are handled by our identity provider (Clerk). Single sign-on (SAML/SSO) for enterprise customers is on our roadmap.
Approval-first execution
Aldwin can prepare an entire campaign autonomously, but anything that leaves your workspace, whether publishing, sending, or launching to an external system, routes through a security gateway and stops at an approval gate. A person reviews and approves external actions before they execute; unknown or high-risk operations fail closed. Generating into your own workspace is never gated; egress to your connected systems always is.
Auditability
Platform actions are recorded in an append-only, hash-chained audit trail. Records cannot be silently altered or deleted, so every automated action can be traced.
Responsible AI
Aldwin is AI-native, and we hold the AI to the same standard as the rest of the product:
- Human approval. AI never publishes or sends on its own; a person approves every external action (see Approval-first execution above).
- No training on your data. We do not use your data to train AI models. Our primary AI provider, Anthropic, is contractually bound to the same under its Data Processing Addendum (in force for Aldwin): it does not train on our inputs and outputs, and does not sell, share, or retain that data outside providing the service.
- Identifier masking. Before third-party records and tool outputs are included in a prompt sent to an AI provider, Aldwin applies automated masking of common personal identifiers.
- Transparency. The full list of AI and infrastructure providers that may process data is published on our Sub-processor page.
Data ownership, export, and deletion
You own your data. You can export your workspace data in a machine-readable format at any time. Workspace deletion runs on a 7-day cancellation window, after which your data is permanently removed from our primary databases and object storage; provider-held analytics, error-monitoring, and backup data expire on each provider's retention schedule. Details are in our Privacy Policy.
What we do not do
- We do not sell your data, and we do not share it for cross-context behavioral advertising.
- We do not use your data to train AI models.
- We do not store or have access to full payment-card numbers.
- We do not access your Customer Data for any purpose other than providing and securing the Service.
Compliance and certifications
- Data processing: Aldwin acts as your processor for customer personal data. A Data Processing Addendum with GDPR Standard Contractual Clauses and UK and Swiss addenda governs that relationship, in force through our Terms.
- CCPA: Aldwin operates as a service provider and does not sell personal information.
- Infrastructure: the Service runs on established cloud providers (Railway, Vercel, Cloudflare) whose data centers carry their own industry certifications.
On the roadmap (not yet complete, and we will not claim otherwise): a SOC 2 Type II assessment, independent third-party penetration testing, and a formal vulnerability-disclosure program. Current security documentation and a security questionnaire are available to customers on request.
Incident response and reporting
- If we confirm a security incident affecting your data, we notify affected customers without undue delay, per the governing agreement and applicable law.
- To report a suspected vulnerability or security issue, contact security@aldwin.io. We aim to acknowledge reports within five business days.
Contact and documents
Security: security@aldwin.io Privacy: privacy@aldwin.io Legal: legal@aldwin.io
Privacy Policy Terms of Service Acceptable Use Sub-processors Cookies