Security and compliance
Your data

Is it safe to give AI your client database?

It is a fair question and it deserves more than a paragraph. Here is what we hold, who can reach it, what it is never used for, and what happens to it when you leave.

The short answer

Your database stays in your CRM, and your CRM stays the system of record. We hold a working copy while your account is open, and it is deleted or returned when it closes.

Nothing you send us trains anybody’s model, and one brokerage’s data is never reachable from another’s.

Straight answers

Eight questions, and where each answer is written down.

None of this is a marketing claim you have to take on trust. Every line is in a document we are bound by, or in a registry you can read.

The questionWhat is trueWhere it says so
Does my data train a model?No. Data sent for composition is not used to train them.Privacy policy
Who writes the messages?Anthropic’s models compose the drafts, on our instructionNamed as a sub-processor
Can another customer reach it?No. Access is scoped per brokeragePrivacy policy
Is it sold, or used for ads?No, and not shared for cross-context advertisingPrivacy policy
Do you hold a copy?Yes, a working copy, while your account is openRetention section
What happens when I leave?Deleted or returned on requestRetention section
Where do my CRM credentials live?Encrypted with a key that is itself split across separate storesSecurity section
Is there an audit trail?Every decision is logged, including the rule that blocked a messageThe guardrail registry

The privacy policy is the binding document and it is written to be read, not to be survived. If a line on this page and a line in that policy ever disagree, the policy wins and we have a bug to fix.

What we hold

A working copy, and nothing you did not ask for.

Reading a lead’s whole history means holding a copy of it. Any vendor claiming otherwise is describing a different product.

Your leads
3 differences
A working copy, while the account is open

Contact and conversation data for the leads you point us at. When your account closes it is deleted or returned on request.

Your CRM copy is yours regardless

The brokerage keeps its own copy in its CRM whatever happens to us. That copy is theirs, not ours, and we never ask you to move off the system you already run.

Opt-outs are kept forever, on purpose

The one thing we never delete. It is the only way to guarantee nobody is contacted again after they said stop.

Your credentials
3 differences
Not sitting in a column

Credentials for connected systems are encrypted with a key that is itself split across separate stores.

Encrypted in transit and at rest

Everything, not just the credentials.

Scoped per brokerage

One customer’s data is not reachable from another customer’s session. On mobile, sessions live in the iOS Keychain and can be locked behind Face ID or Touch ID.

What you can check
3 differences
Every decision is logged

With the rules that fired and the one that failed, written onto your own records.

The rules are published

Every message clears twenty-five guardrails before it sends. Sixteen of them are described in full, and the page says plainly which ones are not and why.

It never claims to be someone else

Messages go out from your office’s own number, in your agent’s name. It never signs as the lead, and it never denies what it is.

The honest answer

What we are not going to promise you.

We hold your data. There is no version of this where we do not. Composing a message out of a lead’s two years of history means reading that history, and reading it means holding it. The questions that matter are how long, who else can reach it, and what it is never used for. Those are answered above.

A third party writes the drafts. Anthropic’s models do the composing. They are named in our privacy policy as a sub-processor rather than buried, and data sent for composition is not used to train them. If using any model provider at all is a hard no for your brokerage, this is the wrong product and we would rather you knew now.

No system is perfectly secure, and our policy says so. If a breach affects your information we will notify you and, where required, the relevant authority. A vendor who will not write that sentence down has not thought about it.

We cannot make your CRM vendor’s security our own. We run inside the system you already chose. What happens to your data inside that system is between you and them, and it was before we arrived.

Questions

AI and your database, answered.

The binding version is the privacy policy. What the engine will and will not say to a lead is on the security page.

Is it safe to give AI access to my CRM?
It depends entirely on what the AI does with it. The questions worth asking any vendor: does my data train a model, can another customer reach it, where do my CRM credentials live, and what happens when I leave. Ours are answered on this page and in the privacy policy.
Does Substrait train AI on my client data?
No. Anthropic's models compose the message drafts, and data sent for composition is not used to train their models. That sentence is in our privacy policy, not just on a marketing page, and Anthropic is named there as a sub-processor.
Can another brokerage see my leads?
No. Access is scoped per brokerage, and one customer's data is not reachable from another customer's session. We also do not use one customer's contact data to benefit another customer, which is a separate promise and is also in the policy.
Do you store my contacts, or only read them?
We store them. Working with a lead's whole history means holding a copy of it, and any vendor telling you they do neither is describing a different product. Your CRM stays the system of record and its copy is yours regardless of what happens to us.
What happens to my data if I cancel?
Contact and conversation data is held for as long as your account is open. When it closes, that data is deleted or returned on request. Opt-out records are the exception and are kept indefinitely, because that is the only way to guarantee nobody is contacted again after saying stop.
How are my CRM credentials stored?
Credentials for connected systems are encrypted with a key that is itself split across separate stores. They are never held as plain text beside the rest of your account, and everything is encrypted in transit and at rest.
Do my leads know they are talking to software?
Messages go out from your office's own number, in your agent's name. Substrait does not volunteer that it is an assistant. Asked directly, it does not deny it. It never signs as the lead and it never claims to be somebody it is not.
One flat rate

Read the policy first. Then let it text you.

One flat monthly rate by database size. No setup fee, no per-message billing, no per-seat billing.