Trust Center

OpenAssistant's security posture, compliance certifications, and policy documents — all in one place.

Security is core to everything we build.

OpenAssistant handles the data you connect — email messages and threads, calendars, contacts, files and documents, and messages on the platforms you link — on behalf of users and their organizations. We take that responsibility seriously. This page summarizes our security and compliance program so you can make an informed decision about trusting us with your data.

Questions? security@openassistant.us — monitored by our security team. Reporting a vulnerability? See Reporting a Vulnerability below.

Certifications & Compliance

SOC 2 Type II
Audited annually by an independent CPA firm.
GDPR Compliant
Data protection rights for EU residents.
CCPA Compliant
Privacy rights for California consumers.
Encrypted in Transit & at Rest
TLS 1.2+ in transit. AES-256 at rest.

Reporting a Vulnerability

If you believe you have found a security vulnerability, email security@openassistant.us, which is monitored by our security team — not by an assistant. We will acknowledge your report within 2 business days, give you our assessment within 10 business days, and keep you updated until it is resolved.

Safe harbour. We will not pursue legal action against anyone who reports a vulnerability in good faith under this policy, and we will not report you to law enforcement. If a third party brings action against you for research conducted under this policy, we will make it known that your research was authorized.

In scope: openassistant.us, app.openassistant.us, and our public APIs. Please report promptly and give us reasonable time to fix an issue before disclosing it publicly.

Please do not access, modify, or retain data belonging to anyone other than yourself; degrade or disrupt the service for other users; use social engineering, phishing, or physical attacks against our staff or customers; or condition a report on payment.

Machine-readable contact details are published at /.well-known/security.txt.

How We Protect Your Data

Encryption
All data encrypted in transit via TLS 1.2+ and at rest via AES-256.
Access Controls
Role-based access and least-privilege principles enforced across all systems.
Annual Pen Testing
Third-party penetration tests conducted annually. Summary available to customers under NDA.
Vendor Management
Sub-processors are security reviewed before onboarding and reassessed periodically.
No AI Training on Your Data
We never train on your data. AI providers are contractually prohibited from doing so.
Data Deletion
Delete your account at any time and we begin deleting your data. What we keep, and for how long, is set out in our Privacy Policy.

Links