> ## Documentation Index
> Fetch the complete documentation index at: https://docs.surfaice.pro/llms.txt
> Use this file to discover all available pages before exploring further.

# Trust FAQ

> Security, privacy, and audit questions IT and compliance teams ask about Hugo.

Answers below describe Surfaice product behavior for enterprise reviewers.

**Quick glossary:** **Hugo** is Surfaice’s in-app AI agent. **Lucernex** is a common lease-administration system of record. **CAM** means common area maintenance (landlord charges tenants reconcile against the lease). For the live compliance summary and NDA document package, use [surfaice.pro/security](https://www.surfaice.pro/security).

If you are new to the product, read [What is Surfaice?](/concepts/what-is-surfaice) first.

<AccordionGroup>
  <Accordion title="Can Hugo send email on my behalf without asking?">
    No. Hugo drafts email and summaries; sending through your connected mailbox requires your explicit action in the product and respects your mailbox permissions. There is no tenant-wide send capability.
  </Accordion>

  <Accordion title="Does Surfaice train on our leases, emails, or documents?">
    No. Customer content is not used to train Surfaice models or vendor models under our commercial agreements. See [Data handling](/concepts/data-handling).
  </Accordion>

  <Accordion title="Can Hugo access data I cannot open in Lucernex or SharePoint?">
    No. Surfaice inherits your existing entitlements. If you cannot open a record outside Surfaice, Hugo should not surface it to you. See [Permissions](/concepts/permissions).
  </Accordion>

  <Accordion title="Can we read the CEO's mailbox tenant-wide?">
    No. Mailbox connectors are per user, granted by that user, and gated by Surfaice role. Admins can disable email connectors for roles that should not use them.
  </Accordion>

  <Accordion title="What is logged in the audit trail?">
    Agent runs record who initiated a request, which tools and connectors were used, and what artifacts were produced. See [Audit trail](/concepts/audit-trail).
  </Accordion>

  <Accordion title="Where is data stored?">
    Each customer environment is isolated on Google Cloud in US regions. Surfaice does not mirror your full DMS or mailbox by default. See [Data handling](/concepts/data-handling).
  </Accordion>

  <Accordion title="What happens if we disconnect or offboard?">
    Connector access stops immediately. Systems of record were never replaced, so there is nothing to unwind in Lucernex or SharePoint. Deletion of limited persisted Surfaice data follows your agreement.
  </Accordion>

  <Accordion title="Can we block HR, legal, or sensitive email topics?">
    Yes. Instance-wide exclusion lists by keyword, sender, domain, and folder apply across email-touching skills.
  </Accordion>

  <Accordion title="Are you SOC 2 certified?">
    SOC 2 Type II is in progress via Vanta (observation period ahead of independent audit), expected Q3/Q4 2026. See [surfaice.pro/security](https://www.surfaice.pro/security) for current status.
  </Accordion>

  <Accordion title="Who do we contact for security questionnaires?">
    Email [security@surfaice.pro](mailto:security@surfaice.pro) for the Security Guide, architecture diagram, and AI governance policy under NDA.
  </Accordion>

  <Accordion title="What if Hugo gives wrong lease or CAM numbers?">
    Treat outputs as drafts. Your team verifies citations before updating systems of record. Report recurring accuracy issues to your Surfaice admin — see [Agent limitations](/concepts/hugo-limitations).
  </Accordion>

  <Accordion title="Can users export chat history?">
    Workspace policy and role determine what can be saved or exported. Sensitive exports should follow your company's data classification rules.
  </Accordion>
</AccordionGroup>

## Related

* [Security overview](/security)
* [Permissions](/concepts/permissions)
* [Data handling](/concepts/data-handling)
* [FAQ](/faq)
