Trust and security at ABRAM
ABRAM is built by Thomas Abram, LLC in Washington, DC. This page describes how the platform handles your data, who we share it with, and what is still in progress. It is updated whenever any of that changes.
Where ABRAM stands today. ABRAM launched in August 2026. SOC 2 and ISO 27001 are on the roadmap rather than in hand today, and the table below says where each one stands. We put that here rather than in an email six weeks into your review. What we do have is described below, in full.
Hosting and infrastructure
| Application hosting | Vercel, United States |
| Database and file storage | Supabase, PostgreSQL, United States |
| Identity and access | WorkOS |
| Payments | Stripe |
| Error monitoring | Sentry |
| Transactional email | Resend |
| AI inference | Anthropic |
Encryption
- Data in transit is encrypted with TLS 1.2 or higher.
- Data at rest is encrypted.
- Payment card data never touches ABRAM infrastructure. Stripe is the processor and, for user-to-user payments, the payee is merchant of record.
Access control
- Row-level security is enforced on every database record, so an organization cannot read another organization's data even if an application-layer bug allowed the attempt.
- Authentication, single sign-on and SCIM directory sync run through WorkOS. SAML SSO and SCIM provisioning are available on the SMB / Enterprise plan.
- Role-based permissions govern what each member of an organization can see and do.
- ABRAM personnel operate under least-privilege access.
Your data and AI
- Customer data is never used to train ABRAM's shared models. Training is a separate opt-in, and it is deliberately not bundled into the Terms of Use.
- Your organization's Company Brain is private to your organization and is never used to train shared models, whatever your consent setting.
- Data sent to Anthropic's API is not used to train their models under their commercial terms.
- Every AI action that writes to your workspace passes an approval gate. The assistant drafts and a person approves.
- Organizations on the SMB / Enterprise plan can disable every AI feature across the company from a single setting.
Privacy and data rights
- ABRAM complies with GDPR, UK GDPR and CCPA.
- Every sub-processor offers data processing terms addressing GDPR Article 28, incorporated into its standard service agreement. Where a provider requires a separately executed Data Processing Agreement or Standard Contractual Clauses, we complete that step before the provider is used in production. The current list is at /subprocessors.
- International transfers rely on the 2021 EU Standard Contractual Clauses and, for the UK, the IDTA or the UK addendum. Transfer Impact Assessments are on file.
- Access, deletion, portability, correction and restriction requests are honored within one month under GDPR and thirty days under CCPA.
- ABRAM does not sell personal information.
Incident response
- Personal data breaches are notified to the relevant supervisory authority within 72 hours where GDPR Article 33 or applicable US state law requires it, and to affected individuals without undue delay where the risk is high.
- All incidents are recorded in an internal breach register.
- Report a suspected incident to legal@abram.network.
What is in progress
We would rather you read this here than discover it in week five of a review.
| Status | |
|---|---|
| SOC 2 Type I | In progress. Target Q2 2027 |
| ISO 27001 | On the roadmap. Target 2028 |
| Third-party penetration test | Planned for 2027 |
| Vulnerability scanning program | Policy set out below. Tooling being contracted |
| EU Article 27 representative | Being appointed |
| HECVAT and VPAT | Available on request |
| FERPA addendum | Planned |
| WCAG 2.1 AA conformance | Partial. Known gaps are listed in our accessibility statement. |
Our remediation commitment. We operate to the following patch timelines for vulnerabilities affecting the platform: critical and emergency within 14 days, high within 30 days, medium within 90 days.
Contact
| Security and incidents | legal@abram.network |
| Privacy and data rights | privacy@abram.network |
| Data controller | Thomas Abram, LLC, Washington, DC |
Our standard Data Processing Agreement is available from legal@abram.network, and we send it within 5 business days of a request. A completed security questionnaire is available the same way. The sub-processor list is public at /subprocessors.