Where we stand today
Trust pages have a habit of listing aspirations as if they were facts. This one doesn't. The left column is shipped and running in production. The right column is work we intend to do and haven't.
In place today
Shipped- Tenant isolation at the database layer. Every customer's data is separated by PostgreSQL row-level security policies, not only by application logic. A bug in our code is not sufficient to leak data between accounts.
- Multi-factor authentication. Time-based one-time passwords with recovery codes, and per-user trusted-device tokens.
- Password hashing with bcrypt. We never store or transmit a password in readable form.
- Encrypted third-party credentials. Integration secrets you give us are encrypted at rest.
- Rate limiting on authentication, chat, and every public endpoint.
- Payment-card redaction. Card-like strings in conversation text are detected and masked automatically. Unmasking requires an explicit permission grant plus a written justification, and is recorded.
- Immutable audit log of sensitive administrative actions — who did what, when, and why.
- Configurable retention with automated purging. A nightly job anonymises conversations past your chosen window without anyone having to remember.
- Self-serve deletion for end users. Your customers can delete their own conversation from the widget, or save a private link to do it later from any device.
- Two-stage account offboarding. Archive is reversible; purge cascades a permanent delete across every table, then cleans up external resources.
- Signed, verifiable webhooks with protection against server-side request forgery on customer-supplied URLs.
- Masked inputs during co-browsing by default, with screen content relayed live and never written to storage.
- TLS in transit across the platform.
Not yet — on the roadmap
In progress- Third-party penetration test. Not yet commissioned. We have not had an external party attempt to break in.
- SOC 2 Type II. No audit has begun. We make no SOC 2 claim of any kind.
- Formal WCAG 2.1 AA audit. Accessibility has been considered throughout, but never formally assessed. Known gaps are named on our Accessibility Statement.
- Encryption-at-rest attestation. Our hosting provider encrypts stored data; we have not yet obtained and published documentation confirming the specifics.
- A documented, rehearsed incident response runbook. Our public commitments are on the Incident Response page, but the internal procedure behind them is not yet written down and drilled.
- A GDPR compliance programme. Including Standard Contractual Clauses and an EU representative. We apply comparable principles today but claim no formal compliance.
- Data residency outside the United States. Not offered.
- Formal subprocessor notice window. We publish changes; we don't yet commit to a fixed number of days' advance notice, because we have no mechanism to deliver one reliably.
The short answers
The questions we'd ask if we were the ones buying.
Do you train AI models on our conversations?
No. Not us, and not our model provider — Anthropic does not train on inputs or outputs submitted through its business API by default. Your conversations are used to answer your customers and for nothing else.
Do you sell or share personal information?
No, and we never have. There is no advertising, no analytics, no data brokerage, and no cross-context behavioural sharing anywhere in the product or on this site.
Can we get our data out?
Yes. Export conversations to CSV from the admin portal at any time — the whole account, a date range, or a single conversation for a subject access request. Conversation events can also stream to your own systems via webhooks or Zapier.
Can we control how long you keep things?
Yes. Set retention between 30 and 180 days; the default is 90. A nightly job anonymises anything past your window automatically. You can also delete individual conversations on a customer's behalf, and your customers can delete their own.
Will you sign our DPA?
Our Data Processing Addendum is published and automatically forms part of your agreement — no signature needed. If your compliance team requires a countersigned copy for their file, email legal@desertdesk.app.
Do you have SOC 2 or a pen test report?
No. Neither exists today, and we won't imply otherwise to win a deal. If your procurement process requires one, we're not the right fit yet — and we'd rather tell you now than in month four.
Where is our data stored?
The United States. All infrastructure and every subprocessor operate there. We don't currently offer regional data residency.
Documents
Everything is public, versioned, and dated. All of it is pending review by counsel.
Privacy Policy
What we collect, why, who sees it, and how long we keep it — separately for site visitors, your staff, and your customers.
Read →Terms of Service
The agreement governing your use of Desert Desk, including billing, suspension, and liability.
Read →Data Processing Addendum
Our obligations as a processor of your customers' personal data. Automatically part of your agreement.
Read →Subprocessor List
Every third party that touches data, what it does, and whether it's always used or only when you enable it.
Read →Incident Response & Data Breach
How we classify incidents, when we'll tell you, what a notification contains, and how to report one to us.
Read →AI & Bot Disclosures
Which models we use, what they can and can't do, and how a person takes over when the AI shouldn't be answering.
Read →Cookie Policy
Two cookies, both necessary, no trackers — and why that means you won't see a consent banner.
Read →Acceptable Use Policy
What Desert Desk may not be used for, and what happens if it is.
Read →Accessibility Statement
Our conformance target, what's been done, and an honest list of the gaps we know about.
Read →Reporting a vulnerability
We don't run a paid bug bounty. We do read every report, and we'll credit you if you'd like us to.
-
Email security@desertdesk.app
Include enough detail to reproduce the issue. If you need to share something sensitive, say so and we'll arrange a secure channel.
-
We acknowledge within two business days
A human replies confirming we've received it and telling you what we understand the issue to be, so you can correct us early if we've misread it.
-
We investigate and keep you posted
You'll hear from us as the assessment progresses rather than only at the end. If we conclude it isn't a vulnerability, we'll explain our reasoning rather than just closing the thread.
-
We fix, then tell affected customers
Where an issue affected customer data, we notify per our Incident Response commitments.
Please don't access or modify data that isn't yours, run automated scans that degrade the service for others, or publicly disclose an issue before we've had a reasonable chance to fix it. Research conducted in good faith along those lines is welcome, and we won't pursue action over it.
Something not answered here?
Security questionnaires, procurement reviews, and awkward questions are all fair game. We'd rather have the conversation than lose you to an unanswered doubt.
Email security@desertdesk.app Visit support