Begrasp.

Trust Center

Trust, at a glance

The short version procurement needs: how we protect your data, who processes it, and where we stand on compliance. For the long form, see Security & Sovereign Ethics.

Tenant isolation

Row-level security on every table — no customer can read another's data. Verified in tests.

Encryption

TLS 1.2+ in transit, encrypted at rest. HSTS on all origins.

No data resale

We never sell personal data and show no ads. Your diagnoses are yours.

On-device voice

Voice intake is transcribed in your browser — raw audio never leaves your device.

Compliance status

Data Processing AgreementAvailable — see the DPA & subprocessor list
GDPR / CCPASupported — access, export, and deletion on request
SOC 2 Type 1In progress — controls implemented; Type 2 to follow
Penetration testPlanned — scheduled pre-GA

Subprocessors

VendorPurposeData
SupabaseDatabase & authenticationAccount, brand, diagnosis data
StripeBilling & paymentsBilling identity (no card numbers stored by Begrasp)
ModalEngine runtimeTransient — reads intake, writes diagnosis
ResendTransactional emailEmail address, message content
VercelApp & site hosting / CDNRequest metadata

Each subprocessor operates under a data-processing agreement. The authoritative, dated list lives on the DPA page.

Engine integrity

Quality gates23 gates — nothing publishes unless all pass
Ethics kill-switchAn operator-proof veto; a halted run ships nothing
ProvenanceEvery generated asset is C2PA-stamped and safety-scanned
AuditabilityDeterministic replay reproduces any run from its inputs

Report something

Security issue: security@begrasp.com · Privacy request: privacy@begrasp.com · Everything else: hello@begrasp.com.

Full security overview Help & FAQ See the plans
TermsPrivacyRefundDPASecurityHome