IProgram status
SOC 2 Type IIIn progressControls implemented; observation window underway.
Data Processing AddendumAvailableSigned on request for every customer agreement.
PII tokenizationEnforcedReversible substitution on every model call — PII never leaves Barkrow infrastructure.
EncryptionTLS 1.2+ · AES-256In transit and at rest across all stores.
HostingMicrosoft Azure · USPrivate networking; no public ingress to data services.
NDAOn requestMutual NDA available before security review.
IIPosture
Built for the PII boundary
Client names, carrier terms and other sensitive information are held out of the model. The marketing surface never sees a customer document.
Append-only by design
Every check is written down and source-linked to the exact clause and page. Nothing is silently overwritten.
Identity & access
Email/Password and social sign-in with required MFA on every plan. OIDC SSO on Pro; SAML SSO and SCIM provisioning on Enterprise.
Full detail lives on the Security, Data Processing and AI Acceptable Use pages. For a security review or signed DPA, get in touch.