Trust
Security & Trust
Maintained by Astraready Technologies Private Limited. This is editable product content describing controls currently enabled in ASTRA. It is not a certification — see the compliance roadmap below.
Authentication
Sign-in is handled by our managed backend provider (Supabase Auth). Passwords are stored as salted hashes, never in plain text. Sessions use signed JWTs with expiry. OAuth (Google, Microsoft) is supported for sign-in and for connecting send-from-inbox.
Access control
Customer content is scoped per account. Row-level security policies in Postgres ensure one user cannot read another user's leads, drafts, business profile or memory. Studio (team) workspaces share content only with confirmed members of that workspace, scoped by `workspace_id`.
Encryption
Traffic is encrypted in transit using HTTPS / TLS 1.2+. Data is encrypted at rest by our cloud database provider. OAuth refresh tokens for connected inboxes are stored in a dedicated table with row-level security restricting reads to the owning user and the server-side send function.
AI processing
Drafts and reasoning calls run through a server-side AI gateway (Google Vertex AI / Gemini). We do not authorise the gateway to train models on your content. Prompts include only the minimum context needed for the action (lead, business voice, the draft being edited).
Sending from your inbox
When you connect Gmail or Outlook, ASTRA only requests the OAuth scopes needed to send and thread email. We do not read your mailbox at all. Replies reach ASTRA only when your provider forwards them to our inbound webhook — never by us polling or listing messages in your inbox. Reply-body content is stored only if you separately opt in to Reply Intelligence (see below). You can disconnect at any time from Settings → Inboxes, which revokes our refresh token and stops all sends.
Reply Intelligence — data controls (opt-in)
Off by default. Reply Intelligence — classification of inbound replies and the reply-patterns dashboard signal — is disabled for every account until you explicitly opt in from Settings → Privacy & AI. Until you do, ASTRA records only the sender email and timestamp on replies; nothing is sent to any AI service.
When you opt in, we store a capped 280-character preview + subject line per inbound reply — never the full body. We classify that preview through the AI gateway above with no training on your content and no cross-user use. Every consent grant, revoke and purge is written to an audit log you can see in Settings.
Retention: stored previews auto-purge after 30 days via a nightly cron. You can revoke consent and purge everything already stored, on demand, from the same tab — one click, no support ticket.
Sub-processors
We use the following third-party services to operate ASTRA. We do not authorise any of them to use your content for their own purposes beyond providing the service to you.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase (managed Postgres + Auth) | Database, authentication, row-level security, storage | AWS — primary region per workspace |
| Google Cloud (Vertex AI / Gemini) | AI gateway for drafting, reasoning, and (only when the user opts in) reply classification | Global routing, no training on customer content |
| Resend | Transactional email delivery (notifications, drafts you send) | US / EU |
| Google (Gmail API, OAuth) | Sending email from your Gmail inbox when you connect it | Per-user |
| Microsoft (Microsoft Graph, OAuth) | Sending email from your Outlook when you connect it | Per-user |
| PostHog | Product analytics — funnel & retention only, no email bodies | EU / US (configurable) |
| Cloudflare | DNS, edge cache and DDoS protection for marketing surfaces | Global edge |
We notify customers of material changes to this list via email and the public changelog.
Data processing addendum (DPA)
Customers on any paid plan can execute our standard DPA at no cost. It incorporates the EU Standard Contractual Clauses where personal data of EU residents is processed. Request the latest copy at legal@astraready.com and we'll counter-sign within one business day.
Compliance roadmap
- Today — RLS-isolated multi-tenant Postgres, encrypted at rest & in transit, OAuth scoped to sending only, audit-trail of admin exports.
- Next 90 days — SOC 2 Type I readiness assessment, formal vendor review cadence, public sub-processor change-log.
- Next 180 days — SOC 2 Type II observation window begins, ISO 27001 gap analysis.
- Customer audits — Available on the Studio plan with a signed NDA.
Customer responsibilities
Use a strong, unique password and enable SSO where available. Sign out of shared devices. Review AI-drafted content before you send or publish. Do not paste confidential third-party material you don't have permission to use.
Report a vulnerability
Email security@astraready.com with details and steps to reproduce. We respond within one business day and credit responsible disclosure in the changelog.
Operated by ASTRAREADY Technologies Private Limited · CIN U62011HR2026PTC147713 · Registered office: B8-903 Tulip Orange, Sector 70, Gurgaon 122101, Haryana, India.