Security, privacy, and compliance are foundational to GhostWriters. We protect your data with enterprise-grade controls and maintain transparency about our practices.
All data encrypted with AES-256 at rest and TLS 1.3 in transit.
Annual SOC 2 Type II audit covering security, availability, and confidentiality.
Full compliance with EU General Data Protection Regulation. DPA available on request.
Annual third-party penetration testing with remediation within 30 days.
Hosted on SOC 2 certified cloud infrastructure with 99.9% uptime SLA.
Enterprise SSO (SAML 2.0, OIDC) and SCIM 2.0 automated provisioning.
User data retained for duration of account. Deleted within 30 days of account closure.
Full data export available in JSON/CSV format from Settings > Data Export.
Account deletion with 7-day cooling period. All data permanently removed after.
Primary data stored in US-East. EU data residency available for Enterprise plans.
Your content is never used to train AI models. Prompts are processed and discarded.
Role-based access (RBAC), MFA, session management, and IP allowlisting.
Third-party services that process data on our behalf. Updated as of May 2026.
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure & hosting |
| OpenRouter | AI model inference |
| Paddle | Payment processing & billing |
| Cloudflare | CDN, DDoS protection, DNS |
| SendGrid (Twilio) | Transactional email delivery |
| Sentry | Error monitoring & performance |
For security inquiries, DPA requests, or compliance questions, contact our security team.
Contact Security Team