Security & Data Protection

Last updated: July 6, 2026

A translation of this document may be provided for convenience. The English version is the authoritative, legally binding version; in case of any conflict, the English version governs.

This document is provided for transparency and is not legal advice. Please consult your own legal counsel about your specific situation.

We understand your conversations, customer records, and device data are sensitive. Here is how the platform protects them.

1. Tenant isolation

Each organization's data is isolated at two independent layers: application-level authorization (every request is scoped to your organization) and database security rules (enforced by Google Firestore, which only permit an organization's members to read that organization's data). No customer can access another customer's data.

2. Credentials & secrets

WhatsApp tokens, email credentials, and device-account credentials are stored in Google Secret Manager (encrypted and access-controlled) — never in the database, application logs, or source code. Logs record operational metadata, not message content.

3. Encryption

All data is encrypted in transit (TLS) and at rest (Google-managed encryption for Firestore, Secret Manager, and Cloud Storage).

4. Access control & auditing

Access to production systems is restricted to authorized personnel under least-privilege IAM, and the application runs as a dedicated, minimally-privileged service account. Administrative and data-access events are recorded in Google Cloud Audit Logs; in-application actions (replies, access grants, impersonation, connection changes) are recorded in a per-organization audit log. We access your content only to provide support you request, under our Data Processing Agreement.

5. Infrastructure

The platform runs on Google Cloud Platform. Media is served through short-lived signed URLs; storage buckets are private and not publicly accessible.

6. Availability

Services run with automatic restart and health monitoring, and we are alerted to outages. Data resides in Google's managed, replicated datastore — a compute incident does not expose or lose data.

7. Deployment options

Most customers run on our hardened multi-tenant platform. For customers with stricter requirements (regulated industries, data residency), we offer a dedicated single-tenant deployment with a separate database and instance.

8. An honest note

We are a managed service provider: for operations and support, authorized personnel can technically access data, governed by access controls, audit logs, and our Data Processing Agreement — this platform is not a "zero-knowledge" system. For cryptographic guarantees, a dedicated deployment is available.

9. Contact & responsible disclosure

Report security concerns to Land AI LLC · dev@landaillc.com