Guide
Is it safe to put company data into AI tools at work?
It's a fair question and it deserves a real answer rather than a badge. The risk isn't the same across tools, and the differences are checkable if you know what to ask. Here are the three questions that actually separate them, and our own answers, including the parts that aren't flattering.
Glitch is live in the chat on our home page. Say what your business needs and it starts working, no signup.
Talk to GlitchWhy the worry is reasonable
The default worry usually comes from consumer AI tools, where the terms have changed more than once and the setting that controls training is buried. Someone on your team pastes a customer list or a contract into a personal account, and now your company's information is in a service your company never agreed to terms with. That's a real exposure and it happens quietly.
The useful response isn't to ban AI, which just pushes it into personal accounts where you can't see it. It's to know which questions distinguish a tool you can put company information into from one you can't.
The three questions that matter
First: is my data used to train models? Second: who can see it, both inside my company and inside yours? Third: where is it stored, and what happens to the keys and passwords I connect? Every serious vendor can answer all three plainly, and an answer that arrives as marketing language instead of a specific is itself an answer.
Ask them of any tool, including this one. The point of writing them down is that they're checkable, and a vendor who gets vague on the second or third question is telling you something worth hearing.
Our answers: training, storage, and keys
Your workspace's content isn't used to train models. Each company's data is isolated to that company at the database level rather than by application code remembering to filter, which is the difference between a rule and a habit. Connection credentials, like the key for your store or your payment account, are encrypted at rest with a key derived separately for your organization, and they're never written to logs, error messages, or audit records.
If you'd rather your AI usage run through an account you control entirely, you can connect your own key from a provider like Anthropic or OpenAI. Everything then runs through your account under your agreement with them, and there's no message limit on any plan, including the free one.
Who can see it inside your own company
This is the question people forget to ask, and in a shared AI it matters more than the vendor question. Answers land in the channel where they were asked, visible to the people in that channel, the same as a colleague speaking in a room. That visibility is the point of a shared assistant, and it's worth being deliberate about which conversations happen where.
Outside people are handled differently and more strictly. When you bring a client, vendor, or contractor into a guest room, the AI answers there with no company data at all, no shared memory and no connected sources. So a guest asking a well-phrased question can't surface something from elsewhere in your workspace, because there's nothing behind it to surface.
The one thing that leaves, described exactly
We send a stream of structural information back to us, and it's on by default, so you should know precisely what it is. It carries the shape of how work went, never the content: which version of a prompt produced which kind of outcome, whether the outcome succeeded, failed, or a human stepped in, the type and severity of a finding, and cost and timing as coarse buckets like under one cent or one to five cents.
What it never carries: your customers' or brands' names, revenue numbers or any specific quantity from your business, and the text of anything, not a brief, not an output, not an audit entry, not what a person said when they intervened. That isn't a policy promise, it's enforced at the database level, which refuses to write anything outside the permitted list. Your admin page lists every event that's been sent and has a single switch to turn it off. It exists so the next version of the work your team runs is better than the one they ran today, and if that trade isn't worth it to you, the switch is right there.
What we don't have
We don't have SOC 2, HIPAA, or ISO certification. If your buying process requires one of those, we're not the right fit today and we'd rather say so than let you find out in a security review. We're a small company building for small teams, and the honest description of where we are is careful engineering without a third-party audit behind it yet.
So the practical advice: for the everyday operating information of a small business, the protections above are the substantive ones. For regulated data, health records, or anything under a contractual security obligation, use a vendor who can hand you the certificate.
Common questions
Do you train models on our data?
No. Your workspace's content isn't used to train models, and the structural stream described above carries no content of any kind, only outcome shapes and coarse cost buckets, enforced at the database level rather than by policy.
Can a client we invite see our internal information?
No. A guest sees only the room they were added to, and inside that room the AI answers with no company data at all, no shared memory and no connected sources. That's a second lock beyond the room boundary itself.
What happens to the keys we connect, like Stripe or our store?
They're encrypted at rest with a key derived separately for your organization, and they never appear in logs, error messages, or audit records. When you save one we run a single real call to confirm it works, then report back what it found, never the key itself.
Are you SOC 2 certified?
No. We don't hold SOC 2, HIPAA, or ISO certification today. If your procurement process requires one, we're not the right fit yet, and we'd rather tell you now than in a security questionnaire.
Keep reading
See it working, not described
Glitch is live in the chat on our home page. Say what your business needs and it starts working. No signup needed.