Security
Your data stays yours. ExecuteIQ is a vendor-neutral intelligence layer that sits on top of your existing tools. We index your data to serve your workspace, and for nothing else.
Every customer's data is isolated at both the application and database layers. There are no cross-tenant reads. Within your workspace, one project's context never surfaces in another project's answers.
ExecuteIQ runs on Google Cloud Platform, with your data hosted in US regions.
Your data is encrypted at rest and in transit. The intelligence layer uses customer-managed encryption keys. Connector credentials are encrypted before storage.
ExecuteIQ connects to your tools through scoped, read-only access. We never write back to your source systems. You choose which projects, spaces, and channels to connect, and you can disconnect any source at any time.
Personal and sensitive data, such as customer PII, financial identifiers, and health information, is automatically redacted before processing. Team member names used for ownership and accountability are retained by design, because knowing who owns what is core to how ExecuteIQ works. A processing control can immediately halt all AI activity.
Transcript ingestion is user-initiated. ExecuteIQ only processes the transcript and meeting files you choose to upload.
ExecuteIQ does not use your data to train AI models. Your data is used only to answer your questions and generate your reports, grounded in your own sources, with citations.
Access is protected by authentication with multi-factor support, and role-based permissions across Admin, Delivery Leader, and Executive roles.
Every significant action in ExecuteIQ is logged, including data ingestion, syncs, Scout queries, report generation, logins, and exports, with user, timestamp, and source. Logs are exportable to your SIEM.
You own your data and can export or delete it.
Disconnect any source and its indexed data is removed. Original uploaded files are held briefly for reprocessing, then automatically deleted.
If you cancel, access is revoked immediately and your data is held in a locked, recoverable state for 30 days in case of error, then permanently deleted.
We honor immediate deletion on request.
Deletion events are logged.
Our compliance approach
We build to GDPR principles from day one. SOC 2 Type II and formal HIPAA support are on our roadmap. ExecuteIQ is an early-stage platform. If you are evaluating ExecuteIQ and have specific security questions, we are glad to walk through our architecture and current posture with your team.
Talk to us about security