Last updated: April 2026
All data stored in AES-256 encrypted databases. Slack OAuth tokens are encrypted at the application layer using AES-256-GCM before being written to disk.
All communications between clients, the ITSquare.AI application, and third-party services use TLS 1.2 or higher. No unencrypted channels.
Row-level security (RLS) is enforced on every database table. One workspace cannot access another workspace's conversations, device data, or knowledge base.
The bot reads only messages it is directly involved in — DMs and @mentions. It does not read channels it hasn't been invited to and never reads messages passively.
We take security reports seriously. If you discover a vulnerability in ITSquare.AI, please report it to us responsibly. We commit to the following:
Report a vulnerability
Send a detailed description of the issue, steps to reproduce, and potential impact to:
brucelee@itsquare.aiPlease include: description, reproduction steps, affected component, potential impact, and your contact info.
ITSquare.AI is an early-stage product. We do not currently hold SOC 2, ISO 27001, HIPAA, or PCI DSS certifications. We are committed to pursuing SOC 2 Type II certification as the product matures. If your organization has specific compliance requirements, contact us at brucelee@itsquare.ai to discuss.