Security

Last updated: 25th July 2025

At Factory AI, we take security seriously and are committed to protecting your data. We work with trusted partners to deliver our services while maintaining the highest standards of security and privacy.

Our Security Approach

We implement comprehensive security measures to protect your data throughout our platform. This includes encryption in transit and at rest, regular security audits, and strict access controls. We carefully select and monitor our subprocessors to ensure they meet our security standards.

Subprocessors

We use the following trusted third-party services (subprocessors) to help us deliver and improve our services. Each of these partners has been carefully evaluated for their security practices and compliance standards.

AWS (Amazon Web Services)

Purpose: Cloud infrastructure and hosting

Data Location: Servers in United States and Australia

AWS provides our cloud infrastructure with enterprise-grade security, compliance certifications, and robust data protection measures.

OpenAI

Purpose: AI model services and responses

Data Retention: Zero data retention agreement in place

We rely on OpenAI's models to provide AI responses.

Anthropic

Purpose: AI model services and responses

Data Retention: Zero data retention agreement in place

We rely on Anthropic's models to provide AI responses.

Slack

Purpose: Internal communication tool

Data Usage: Limited to debugging purposes

We use Slack for internal team communication. We may share snippets of data in our internal chats for debugging purposes only.

Google Workspace

Purpose: Collaboration and productivity tools

Data Usage: Limited to debugging purposes

We use Google Workspace for collaboration and internal communications. We may share snippets of data in our internal emails for debugging purposes only.

Sentry

Purpose: Error monitoring and performance tracking

Data Usage: Automatic error reporting and performance monitoring

We use Sentry to monitor errors and performance in our application. Data is never explicitly sent, but may appear in reported errors for debugging purposes.

Stripe

Purpose: Payment processing and billing

Data Stored: Personal billing information (name, credit card, address)

Stripe handles all payment processing and stores your billing information securely. They are PCI DSS compliant and maintain industry-leading security standards for financial data.

Data Protection

We ensure that all our subprocessors meet strict security and privacy requirements. This includes:

  • Compliance with relevant data protection regulations
  • Implementation of appropriate technical and organizational security measures
  • Regular security assessments and audits
  • Contractual commitments to protect your data
  • Zero data retention agreements where applicable

Updates to This List

We may update this list of subprocessors from time to time as we improve our services or change our infrastructure. We will notify users of any material changes to our subprocessor arrangements.

Contact Us

If you have any questions about our security practices or subprocessors, please contact us at support@f7i.ai.