Skip to main content
Canonical source: Compliance claims (SOC 2 status, subprocessors, training, contractual commitments) live on surfaice.pro/security. This page summarizes product behavior for doc readers and must not outclaim that page.
This page summarizes security topics for product users and reviewers. The live, questionnaire-oriented write-up lives on the marketing site and is the preferred link for IT reviews. Hugo is Surfaice’s in-app AI agent. When other pages say “agent requests” or “agent runs,” they mean work Hugo performed in a customer workspace.

Full security page

Enterprise security summary, subprocessors, compliance status, and NDA package request.

Highlights

  • Permissions inherited from source systems; Surfaice does not expand entitlements — see Permissions
  • Per-user mailbox connections — no tenant-wide mailbox read
  • Isolated customer environments on Google Cloud (US regions)
  • No customer data used to train models (contractual)
  • Audit trail of agent requests — who asked, what tools ran, what was produced
  • SOC 2 Type II — in progress via Vanta (observation period ahead of independent audit), expected Q3/Q4 2026; see surfaice.pro/security

In-product trust docs

These pages complement the marketing security summary:

Documents under NDA

Request the Security Guide, Application Architecture Diagram, and AI Governance Policy via security@surfaice.pro.

Vulnerability disclosure

Report security issues under our vulnerability disclosure policy.