We keep the data story specific. If a location, vendor, or encryption claim appears here, we should be able to evidence it in our architecture and DPA.
All customer data is stored in the EU.
Application delivery and edge security run through Cloudflare.
Our full sub-processor list is available in our DPA. No surprise vendors, no resellers.
Encryption in transit with TLS 1.2+ and encryption at rest with AES-256 on systems handling customer data.
Customer data access is not a standing privilege. It is an exception that needs a reason, your approval, and a log.
No Grasp employee has standing access to customer data.
Support access requires your written approval, is time-bound, and is logged.
Our internal tooling sits behind zero-trust access with enforced MFA and a strict allowlist. We run the same discipline we sell.
The AI estate data you share with Grasp is used to provide Grasp to you. It is not raw material for training models.
Customer data is never used to train, fine-tune, or evaluate AI models. Ours or anyone else's.
For Greppy, our AI agent, we will show the model-provider terms that apply to customer data under NDA.
We will put this in your contract, not just on this page.
We will not claim certificates, reports, or control coverage before we have the evidence. Here is the current state.
We are a Dutch company (Traece B.V., Amsterdam) built under the GDPR from day one. Signed DPA, sub-processor list, and data subject rights handling are available on every plan.
We operate our ISMS to ISO 27001 standards today and certification is on our roadmap. We can walk you through our control implementation under NDA. We will not claim the certificate before we hold it.
We build EU AI Act compliance tooling, and we apply the Act's deployer obligations to our own use of AI: documented purpose, human oversight, and transparency for Greppy.
Your data should remain useful to you and removable when the relationship ends.
One-click export of your data at any time.
On termination: full export on request, then permanent deletion after the agreed wind-down period.
Email info@joingrasp.com. We respond within 2 business days and we do not pursue good-faith researchers.
Send vulnerability reports to info@joingrasp.com. Include affected URLs, reproduction steps, impact, and a safe way to contact you.
Good-faith research is welcome. Please avoid privacy violations, data destruction, service disruption, and accessing customer data.
Short answers only. Anything more detailed can be discussed under NDA.
TLS 1.2+ in transit, AES-256 at rest, across all systems that handle customer data.
In the EU. Sub-processor list with locations is in our DPA.
No. Never, and it is contractually excluded in our DPA.
Not yet. We operate to the standard today and certification is on the roadmap. Ask us anything about our controls; we will answer under NDA.
No one at Grasp by default. Support access requires your written approval and is fully logged.
