What we do. What we don't. What we can't.
Last reviewed: 2026-05-04
If you're evaluating COS for client work, sensitive content, or anything you'd be uncomfortable seeing in a leak, this page is the unvarnished version. We are a privacy-first product run by a small team. We don't use the word "enterprise-grade" to describe ourselves until we've actually earned the badges. Here is exactly where we stand today.
Project data — Brand Voice, Personas, Files, Instructions — is encrypted with a key that lives only in your browser. We literally cannot decrypt it on our end.
COS analysis and chat run on the Anthropic Claude API. Anthropic's API terms prohibit training on customer inputs.
All databases and files are hosted in the U.S. We do not currently offer EU or other regional data residency.
We are privacy-first by architecture, but we have not pursued SOC 2 certification yet. It's on the roadmap, not the wall. If your procurement requires it today, we are not the right fit yet.
When you send a message in chat or run an analysis, your prompt and any project context attached to it are sent directly to the Anthropic Claude API for processing. Anthropic's API terms (commercial terms) prohibit using API inputs to train Anthropic's models. The response is returned to your browser and displayed.
Saved project data — Brand Voice settings, Personas, uploaded Files, custom Instructions, Campaign Notes, and conversation history pinned to a project — is stored in our database with at-rest encryption. The decryption key is derived from a browser-side identifier we call privacy_id. Without that browser's privacy_id, the stored content is opaque ciphertext to us.
Practical implications:
Your account email, login session metadata, and billing records are stored in plaintext (these are operational data we need to read). Payment processing is handled by Stripe; we do not store card numbers on our servers.
If any of the above are non-negotiable for your procurement process, we'll be honest with you up front and you should pick a different tool today.
If you've found a vulnerability or have a security question, email security@semalytics.com. We respond to verified reports within 72 hours.