Trust and security at ABRAM

ABRAM is built by Thomas Abram, LLC in Washington, DC. This page describes how the platform handles your data, who we share it with, and what is still in progress. It is updated whenever any of that changes.

Where ABRAM stands today. ABRAM launched in August 2026. SOC 2 and ISO 27001 are on the roadmap rather than in hand today, and the table below says where each one stands. We put that here rather than in an email six weeks into your review. What we do have is described below, in full.

Hosting and infrastructure

Application hostingVercel, United States
Database and file storageSupabase, PostgreSQL, United States
Identity and accessWorkOS
PaymentsStripe
Error monitoringSentry
Transactional emailResend
AI inferenceAnthropic

Encryption

  • Data in transit is encrypted with TLS 1.2 or higher.
  • Data at rest is encrypted.
  • Payment card data never touches ABRAM infrastructure. Stripe is the processor and, for user-to-user payments, the payee is merchant of record.

Access control

  • Row-level security is enforced on every database record, so an organization cannot read another organization's data even if an application-layer bug allowed the attempt.
  • Authentication, single sign-on and SCIM directory sync run through WorkOS. SAML SSO and SCIM provisioning are available on the SMB / Enterprise plan.
  • Role-based permissions govern what each member of an organization can see and do.
  • ABRAM personnel operate under least-privilege access.

Your data and AI

  • Customer data is never used to train ABRAM's shared models. Training is a separate opt-in, and it is deliberately not bundled into the Terms of Use.
  • Your organization's Company Brain is private to your organization and is never used to train shared models, whatever your consent setting.
  • Data sent to Anthropic's API is not used to train their models under their commercial terms.
  • Every AI action that writes to your workspace passes an approval gate. The assistant drafts and a person approves.
  • Organizations on the SMB / Enterprise plan can disable every AI feature across the company from a single setting.

Privacy and data rights

  • ABRAM complies with GDPR, UK GDPR and CCPA.
  • Every sub-processor offers data processing terms addressing GDPR Article 28, incorporated into its standard service agreement. Where a provider requires a separately executed Data Processing Agreement or Standard Contractual Clauses, we complete that step before the provider is used in production. The current list is at /subprocessors.
  • International transfers rely on the 2021 EU Standard Contractual Clauses and, for the UK, the IDTA or the UK addendum. Transfer Impact Assessments are on file.
  • Access, deletion, portability, correction and restriction requests are honored within one month under GDPR and thirty days under CCPA.
  • ABRAM does not sell personal information.

Incident response

  • Personal data breaches are notified to the relevant supervisory authority within 72 hours where GDPR Article 33 or applicable US state law requires it, and to affected individuals without undue delay where the risk is high.
  • All incidents are recorded in an internal breach register.
  • Report a suspected incident to legal@abram.network.

What is in progress

We would rather you read this here than discover it in week five of a review.

Status
SOC 2 Type IIn progress. Target Q2 2027
ISO 27001On the roadmap. Target 2028
Third-party penetration testPlanned for 2027
Vulnerability scanning programPolicy set out below. Tooling being contracted
EU Article 27 representativeBeing appointed
HECVAT and VPATAvailable on request
FERPA addendumPlanned
WCAG 2.1 AA conformancePartial. Known gaps are listed in our accessibility statement.

Our remediation commitment. We operate to the following patch timelines for vulnerabilities affecting the platform: critical and emergency within 14 days, high within 30 days, medium within 90 days.

Contact

Security and incidentslegal@abram.network
Privacy and data rightsprivacy@abram.network
Data controllerThomas Abram, LLC, Washington, DC

Our standard Data Processing Agreement is available from legal@abram.network, and we send it within 5 business days of a request. A completed security questionnaire is available the same way. The sub-processor list is public at /subprocessors.