Copilotly

Legal

Security

How your data is protected, what we deliberately do not claim, and how to tell us if you find something wrong.

Effective · Last updated

How your data is protected

In transit and at rest

All traffic uses TLS 1.2 or above. Stored data - conversations, uploaded documents, account records - is encrypted at rest with AES-256.

Access control

Production access requires multi-factor authentication and is limited to staff whose role requires it. Administrative access is logged, and those logs are retained for 90 days.

Nobody at Copilotly reads your conversations in the ordinary course. The three circumstances in which someone might are set out in the privacy policy, and access under each is logged.

Infrastructure

Hosted on Amazon Web Services, in US regions. Backups are encrypted and rotate on a 30-day cycle, which is why deletion takes up to 30 days to propagate rather than being instant.

Payments

We do not store card numbers. Stripe handles web payments and RevenueCat handles mobile subscriptions; we receive the last four digits, the card type and whether the charge succeeded.

What we do not claim

No system is perfectly secure, and a security page that implies otherwise is a marketing document rather than a security document.

Specifically: Copilotly is not HIPAA-covered, and your conversations are not protected health information under that regime. It is not a financial institution under GLBA. Your conversations are not subject to attorney-client privilege.

Those are not technical limitations we plan to fix - they are consequences of what this product is. If you need a HIPAA-covered service, you need a covered entity, and no amount of encryption changes that.

SOC 2 documentation is available to Enterprise customers under NDA. Contact [email protected].

Reporting a vulnerability

If you have found a security issue, we want to hear about it. Email [email protected] with enough detail to reproduce it.

What we commit to

  • Acknowledging your report within 2 business days
  • Keeping you updated on progress rather than going silent
  • Crediting you publicly if you would like to be credited
  • Not pursuing legal action against good-faith research that follows the guidelines below

What we ask

  • Give us reasonable time to fix it before disclosing publicly - 90 days is the norm
  • Do not access, modify or delete data belonging to anyone else
  • Do not degrade the service for other users - no automated scanning at volume, no denial of service
  • Test against your own account rather than someone else's

We do not currently run a paid bug bounty. We will say so plainly rather than implying one exists.

If something goes wrong

If a breach affects your personal data and creates a risk to you, we will notify you directly and notify the relevant regulator within the timeframes the law requires - 72 hours to a supervisory authority under GDPR.

The notification will say what happened, what data was involved, what we have done, and what you should do. It will not be a vague message about "an incident affecting some users", because that is a form of words designed to minimise rather than inform.

Your side of it

Use a strong, unique password, or sign in with Google and let it handle that. Enable two-factor authentication where offered. Sign out on shared devices.

And the one specific to this product: think about what you paste in. A copilot conversation is stored, is sent to a model provider to generate a response, and is not legally privileged. Most of the time that is fine. For the small number of things where it is not, the safest control is the one you apply before typing.