Security at ProductBridge

Security at ProductBridge

Security at ProductBridge

How ProductBridge stores, processes and protects customer data, documented in full for the teams responsible for reviewing it.

Last updated 8 September 2026

Where we stand on compliance

We are a small team, and we have not completed a SOC 2 Type II audit yet. Rather than leave you to guess what that means, this page sets out exactly what we do have in place — most of which you can verify yourself — and we will answer any security questionnaire you send us.

Data stays in the EU

Database and files in Paris

No model training

Your data never trains an AI model

Encrypted end to end

TLS 1.2+ in transit, AES-256 at rest

Access is logged

Every administrative access is recorded

How we handle your data

The controls that are actually in place today, described specifically enough that you can check them.

No training on your data

Your data is never used to train AI models, ours or our providers’. AI requests go through the OpenAI API, which does not train on data submitted to it.

Data residency and hosting

ProductBridge runs on AWS. Your database and files sit in eu-west-3 (Paris) and vector search in eu-central-1 (Frankfurt). AI processing is the exception, and takes place outside the EU under Standard Contractual Clauses.

Encryption

All traffic uses TLS 1.2 or higher, and data at rest is encrypted with AES-256. Credentials for connected tools are encrypted again inside the application, so a database dump alone does not expose them.

Retention and deletion

We keep your data for as long as your account is open, with no automatic expiry. Ask us to delete anything and it is gone from live systems and backups within 30 days — including one customer’s records for a subject access request.

Backups and recovery

Daily automated backups, retained for seven days, with point-in-time recovery to the last five minutes. Restores are best-effort; we do not offer a contractual RTO or RPO yet.

Authentication

Sign in with email and password or a social provider. Passwords are hashed and sessions use signed, HTTP-only, Secure cookies. SAML and SSO are not self-serve today — contact us if you need them on the Business tier.

Subprocessors

Every third party that processes customer data on our behalf, taken from what actually runs in production — not from a template.

Subprocessor

Purpose

Data processed

Location

Subprocessor

Amazon Web Services (RDS)

Purpose

Primary application database

Data processed

All customer, feedback and support data

Location

eu-west-3 · Paris

Subprocessor

Amazon Web Services (S3)

Purpose

File and attachment storage

Data processed

Uploads and attachments

Location

eu-west-3 · Paris

Subprocessor

Qdrant Cloud

Purpose

Vector search and duplicate detection

Data processed

Feedback text embeddings

Location

eu-central-1 · Frankfurt

Subprocessor

OpenAI

Purpose

AI processing: extraction, summarisation, support agent

Data processed

Feedback and conversation text

Location

Subprocessor

Voyage AI

Purpose

Text embeddings for semantic search

Data processed

Feedback text

Location

Subprocessor

Resend

Purpose

Transactional and notification email

Data processed

Email addresses and message content

Location

Subprocessor

Brevo

Purpose

Marketing contact sync

Data processed

Email addresses

Location

European Union

Subprocessor

Better Stack

Purpose

Application logging and uptime monitoring

Data processed

Application and access logs

Location

European Union

Subprocessor

Cloudflare

Purpose

DNS, CDN and custom domains

Data processed

Traffic metadata

Location

Global edge network

Subprocessor

Inngest

Purpose

Background job orchestration

Data processed

Job payloads

Location

Europe

Before we add a new one

We give 30 days’ notice before a new subprocessor starts handling customer data. To get those notices by email, write to help@productbridge.io with “subprocessor notices” in the subject and we will add you to the list.

Tools you connect yourself

Connecting an integration sends data to that provider on your instruction. Intercom, Zendesk, Jira, Linear, ClickUp, GitHub, Salesforce and Discord only receive data once you connect them, and disconnecting stops it.

Incidents and disclosure

What we owe you if we get something wrong, and how to tell us when you find it first.

If something goes wrong

If customer data is breached, we tell you within 72 hours of becoming aware of it. Notice goes to the account owner of every affected organisation and to any security contact you have given us. It says what happened, which data was involved, what we have already done, and what we suggest you do.

Reporting a vulnerability

Send security reports to help@productbridge.io and we will acknowledge them within three business days. We will not pursue legal action against anyone doing good-faith research who reports privately, does not access or change other people’s data, does not degrade the service, and gives us reasonable time to fix the issue before publishing it.

Questions security reviews always ask

Short answers, no hedging.

Do you train AI models on my data?

Where is my data stored?

Are you SOC 2 certified?

Can I sign a DPA?

How long do you keep my feedback data?

Can I delete a single customer’s records?

Who at ProductBridge can access my data?

What happens to my data if I cancel?

A security question this page does not answer?

Send it to us. We would rather answer something awkward than have you guess from a vague page.

@ProductBridge - 2026 All rights reserved | Made with 🖤 in 🇺🇸 🇮🇳 🇩🇪

@ProductBridge - 2026 All rights reserved | Made with 🖤 in 🇺🇸 🇮🇳 🇩🇪

@ProductBridge - 2026 All rights reserved | Made with 🖤 in 🇺🇸 🇮🇳 🇩🇪