What we do with your data, plainly.
The facts a security review asks for first. Nothing here is a claim we cannot back.
Where your data lives
Your organisation’s data (the database, uploaded files and user accounts) is stored in the European Union, in Ireland, with our database provider Supabase.
A few services that power specific features may process data outside the UK and EU: AI features (Anthropic), email (Resend), maps and drive times (Mapbox) and application hosting (Vercel). Our privacy policy lists each one, what it sees and the safeguards we rely on.
How it is protected
Data is encrypted in transit (HTTPS) and at rest. Each organisation’s data is separated by access rules in the database itself, and every request is checked against who you are, which organisation you belong to and which sites you may see.
Access inside your organisation follows roles you control, down to individual sites and clients.
A record of everything
Every change in Graicx is written to an audit log: who did it, what changed and when. Compliance evidence is stored against the asset with a timestamp and the person who captured it. Both can be exported for an auditor.
AI, under your control
Milo proposes and your rules and people decide. Content sent to the AI is used only to produce the answer and is never used to train third-party models.
Your data stays yours
Export your work orders, requests, assets, actions and compliance records as CSV at any time. If you leave, we delete or return your data on request.
Certifications, honestly
We are a young company. We do not hold ISO 27001 or SOC 2 today, and we will not claim them until we do. Send us your security questionnaire instead: we answer in writing within two business days, and we will sign your data processing agreement.
Report a vulnerability
If you believe you have found a security issue, email security@graicx.ai. We will acknowledge it quickly and keep you updated while we fix it.