← Sloe Laboratory

Sloe Laboratory

Trust

Last updated 3 August 2026SLOE Labs Inc.

Everything we can tell you about how your data is handled, in one place.

You are being asked to put real operational data into a system you did not build. That deserves specifics rather than a badge. Nothing on this page is a claim we cannot show you the evidence for.


Start here#

Security OverviewThe technical detail — isolation, encryption, agent controls. Written for a reviewer who wants specifics, including a section on what we don't have.
Sub-processorsEvery third party that can touch your data, what they do, and where they run. Updated before a new one goes live.
Data Processing AddendumThe contract that makes it binding. GDPR Art. 28, EU Standard Contractual Clauses, and a POPIA operator agreement for South African businesses.
Privacy PolicyWhat we collect and why.
Cookie PolicyEssential cookies only. No analytics, no advertising, no trackers.
Acceptable Use PolicyWhat you may not do here, including agent-specific limits.
Terms of ServiceThe commercial terms.

The four questions people actually mean#

"Can another customer see my data?"#

No. Every record carries an owner and the database itself enforces it, not just the application on top. As at our May 2026 internal audit: all 31 customer-data tables have row-level security enabled — zero run with it off — across 47 policies. The application separately verifies ownership on every request. Two independent layers, either of which would stop a cross-tenant read.

"Does the AI learn from my business?"#

No. We do not train models on your content, do not use it to build features for other customers, and do not use it for advertising. Our AI providers are on commercial terms that contractually bar them from training on what we send and from human review of it. That is a contract, not a setting.

"What can the agent do without asking me?"#

Only what the permissions you granted allow. Every action against a connected service is written to an audit log you can inspect. An independent verifier checks the agent's claims against what actually happened, so "I sent that" is corroborated rather than trusted. Outbound email sends only from a domain you have verified, never from an address the model picked, and only after you confirm.

"What happens to my credentials?"#

We never see your passwords. For most integrations the access grant is held by our connector provider, Composio — we store a reference, not your credentials, and we say so rather than implying a smaller blast radius than exists. Where we hold a credential directly it is AES-256-GCM encrypted with a purpose-derived key. You can revoke any connection at any time.


Where we are today#

Here's the current state of our security program, so you don't have to pull it out of us on a call.

Certifications — Not SOC 2 or ISO 27001 certified. You can have our architecture (this page), our internal audit, and a completed security questionnaire — SIG Lite, CAIQ, or your own — usually within a day.

Penetration testing — No independent test of the current architecture yet. If your review needs one, tell us early and we'll scope it with you.

Uptime — No contractual SLA on standard plans. We monitor continuously and will show you the real numbers. Formal SLA with service credits is available on annual contracts.

Data controls — Keys are managed by us and our infrastructure providers. Tenants share infrastructure with logical isolation. Customer-managed keys, data residency, and single-tenant deployment are on the roadmap, not available today.


For a security review#

Send us your questionnaire and we will return it, usually same-day. Most answers already exist in the Security Overview. We will also sign a DPA before you send us anything sensitive.

security@sloelabs.com — vulnerability reports. We will not pursue legal action against good-faith research that respects user privacy and gives us reasonable time to fix. See AUP §5.

privacy@sloelabs.com — data protection questions, DPA requests, and data subject requests. We answer within 30 days, and usually one business day.

SLOE Labs Inc. — a Canadian federal corporation (number 1781545-0), registered in Ontario.