Security

What stays on your device, what we store, and who can see it.

On your device

Simulation
Every analysis runs in your browser. Waveforms are computed locally and are never uploaded.
Unsaved work
Designs you have not saved to the cloud stay in your browser's storage.

In transit and at rest

Encryption
Every connection uses HTTPS. Stored data is encrypted at rest by our database and hosting providers.
Keys
Database service keys, model keys and payment keys live only on the server. None of them reach the browser.

Access control

Row-level security
Postgres itself decides who can read or change each design, comment and conversation, so the browser can only ever reach what its user is allowed to.
Sharing
Joining a design goes through a server-side check of a live share link or an invite to a verified email address.
Roles
Owners control sharing. Editors change content, commenters comment, viewers read.

The assistant

Where requests go
Your message and the circuit it works on are sent to Azure OpenAI under Microsoft's enterprise terms.
Retention
We ask Azure not to store responses, and your data is not used to train models.
Spend limits
Every request is charged against your allowance on the server before the model runs, so no client can exceed it.

Your account

Sign-in
Email addresses are confirmed with a one-time code. Passwords are stored only as salted hashes. Google, Microsoft and single sign-on are available.
Deletion
Delete your account from Settings. Your designs, conversations and billing customer are removed with it.

Processors

The full list is in the privacy policy.

Supabase
Accounts and database, United States
Vercel
Hosting and analytics
Microsoft Azure
AI models, and Microsoft sign-in if you choose it
Google
Google sign-in if you choose it
Stripe
Payments and tax
Resend
Account emails

Report a vulnerability

Email the details and how to reproduce them. We reply to every report.

contact@surfplatforms.com