Sense6
Trust center

Your data, protected at every step.

How we keep Sense6 secure, private and reliable: what's in place today, in plain language.

Last security scanOctober 5, 2026
Last access reviewEvery 90 days
EncryptionTLS · AES-256-GCM
Data locationBoston, United States

Protecting your data

Encrypted connectionsEvery connection to Sense6 uses TLS, with HSTS so browsers never fall back to an unencrypted one. Mail apps connect over TLS too.
Encrypted credentialsPasswords to connected accounts, access tokens for mail, calendars and banks, and sign-in certificates are encrypted with AES-256-GCM before they're stored.
Passwords never storedSense6 keeps only a salted scrypt hash of your password, and limits sign-in attempts per account and per address.
Nightly backupsThe database is backed up every night, encrypted and kept for 14 days, and a backup is restored into a scratch database every month to prove it works, so a mistake or failure can be undone.

Your workspace is yours alone

Isolation in the databaseEvery table has row-level security: the database itself only returns rows from your workspace, so a bug in one query can't show another company's data.
Permissions on everythingDocs, files, meetings, channels and mail each have their own access list. Search and the AI see only what the person asking can open.
Admin controlsWorkspace admins manage people, roles, retention and legal holds. Every admin change is recorded in the audit log.

Sign-in and accounts

Two-step sign-inAuthenticator apps with one-time recovery codes. Admins can see who uses it.
Company sign-inMicrosoft, Google, any OpenID Connect provider or SAML 2.0, which admins can require. SCIM creates and removes accounts automatically.
Sessions you controlSee every signed-in device in Settings and sign any of them out. Removing someone signs them out everywhere at once and revokes their app passwords.

AI and your information

Never used for trainingSense6 calls AI models through their providers' business APIs, which don't train on what's sent. We don't train models on your data either.
Only what you can seeThe assistant answers from what the person asking has access to, through the same permission checks as the rest of Sense6.
You approve actionsBefore the AI sends mail, posts, or changes data in a connected system, it asks, unless you told it an action doesn't need asking. Every step it takes is in the audit log.
Protected from tricksEmail, documents, web pages and tool results are marked as untrusted before a model reads them, so instructions hidden in them aren't followed.
Your regionUS and EU workspaces use AI providers in their own region.

How we run the service

Where it runsSense6 runs on dedicated servers at Hostinger · Boston, United States. Cloudflare sits in front of it for DNS, encrypted connections and protection from attacks.
Locked-down serversServer sign-in uses keys only (no passwords), the app runs in containers as an unprivileged user, and only the ports for the website, mail apps and server sign-in are open.
Weekly security scansEvery week the server, the app's containers and its dependencies are scanned for known vulnerabilities and leaked secrets, and checked against end-of-life dates. Fixes ship as updates.
Access reviewsEvery 90 days we review who has access to the servers, source code, and each outside service, and record it.
Tested before releaseEvery change is type-checked and runs through unit, integration and end-to-end browser tests before it's deployed.

Privacy and your rights

Export and deleteEveryone can download all of their own data from Settings, and any document, sheet or file in standard formats; admins can export everything shared in the workspace and the audit log. When a workspace is deleted, everything in it is deleted and its bank connections are released at Plaid.
Banks, read-onlyBank connections go through Plaid and are read-only. Disconnecting a bank removes Sense6's access at Plaid, too.
Google dataInformation from Google APIs is used only to provide the features you use, under Google's Limited Use requirements. It's never sold or used for ads.
If something goes wrongWe follow a written incident response plan and tell affected customers without undue delay when an incident affects their data.

Compliance

Sense6 is run to SOC 2 standards: written policies, access reviews, vulnerability management, change testing and an audit trail. An independent SOC 2 audit is in preparation; we don't claim a certification we haven't earned.

Customers can ask for our security policies: information security, access control, encryption and network security, secure development and vulnerability management, privacy and data retention, and incident response.

Request them at [email protected].

Subprocessors

The companies that process data so Sense6 can work. Services you connect yourself (like your Google or Microsoft account) aren't listed: you choose them.

Report a security problem

Found a vulnerability? Email [email protected]. We reply within two business days and keep you updated until it's fixed. We won't take action against good-faith research that avoids privacy violations, data destruction and service disruption.

Machine-readable details are in security.txt.

See also our Privacy policy and Terms of service.