Security
What stays on your device, what we store, and who can see it.
On your device
- Simulation
- Every analysis runs in your browser. Waveforms are computed locally and are never uploaded.
- Unsaved work
- Designs you have not saved to the cloud stay in your browser's storage.
In transit and at rest
- Encryption
- Every connection uses HTTPS. Stored data is encrypted at rest by our database and hosting providers.
- Keys
- Database service keys, model keys and payment keys live only on the server. None of them reach the browser.
Access control
- Row-level security
- Postgres itself decides who can read or change each design, comment and conversation, so the browser can only ever reach what its user is allowed to.
- Sharing
- Joining a design goes through a server-side check of a live share link or an invite to a verified email address.
- Roles
- Owners control sharing. Editors change content, commenters comment, viewers read.
The assistant
- Where requests go
- Your message and the circuit it works on are sent to Azure OpenAI under Microsoft's enterprise terms.
- Retention
- We ask Azure not to store responses, and your data is not used to train models.
- Spend limits
- Every request is charged against your allowance on the server before the model runs, so no client can exceed it.
Your account
- Sign-in
- Email addresses are confirmed with a one-time code. Passwords are stored only as salted hashes. Google, Microsoft and single sign-on are available.
- Deletion
- Delete your account from Settings. Your designs, conversations and billing customer are removed with it.
Processors
The full list is in the privacy policy.
- Supabase
- Accounts and database, United States
- Vercel
- Hosting and analytics
- Microsoft Azure
- AI models, and Microsoft sign-in if you choose it
- Google sign-in if you choose it
- Stripe
- Payments and tax
- Resend
- Account emails
Report a vulnerability
Email the details and how to reproduce them. We reply to every report.
contact@surfplatforms.com