Back to 800

Legal

Security & subprocessors

Last updated: 30 July 2026

This page summarises how 800 protects Customer Content in production, where data is processed, and which providers help deliver the service. It describes controls we maintain; it does not claim certifications we have not earned, and it does not guarantee that incidents cannot occur. For personal-data roles and rights, see the Privacy Notice. For commercial terms, see the Terms of Service.

Product surface

Marketing and product: eight-hundred.app and app.eight-hundred.app. Uploads, runs, credits, and exports happen after sign-in with a company email (or an allowed Google Workspace account).

Data locations

How we protect data

  • Transport encryption

    Production traffic to eight-hundred.app and app.eight-hundred.app uses HTTPS so browsers connect over TLS.

  • Password handling

    Passwords are hashed with scrypt and never stored in plain text. Google sign-in never shares your Google password with 800.

  • Signed sessions

    Sessions are issued by Auth.js. Session secrets stay server-side. Signing out ends the session for that browser. Sessions last up to 30 days unless you sign out sooner.

  • CSRF protection

    State-changing product and auth requests are checked against the expected app origin so forged sites cannot trigger actions as you.

  • Fresh Google sign-in

    Google OpenID Connect requires a fresh re-authentication. We verify ID tokens (including auth_time) before creating a session.

  • Company-email gate

    Self-serve signup requires a company email. Common consumer providers are blocked.

  • Payment integrity

    Stripe Checkout is hosted by Stripe under Managed Payments. Webhooks are signature-verified before credits are granted. We do not store full card numbers.

  • Abuse resistance

    Rate limits apply on sign-in, document runs, and other sensitive endpoints to reduce brute-force and flood risk.

  • Tenant scoping

    We use tenant-scoping and access controls designed to prevent one customer from accessing another customer’s projects through the product.

  • Server-only secrets

    API keys, database credentials, Stripe secrets, and auth secrets live in the server environment. They are not shipped to the browser.

  • AI provider errors

    Raw provider errors are not shown to end users. Runs fail with safe product messaging while details stay in server logs for operators.

  • Analytics hygiene

    Product analytics (PostHog EU Cloud) identify signed-in users by internal account ID and email domain, not full email. Event properties are limited so document text and model output are not sent.

AI processing

Fireworks AI (Fireworks.ai, Inc.) is the inference processor: its infrastructure receives and processes extracted document text for a run. A Kimi-family open-weight model runs on that infrastructure. The model weights do not themselves have a legal location.

Our application calls Fireworks' Chat Completions API. Customer Content is stored in the EU (Ireland). For each run we send only the extracted text and instructions required for that run. Fireworks may process the request in the United States. Under Fireworks' published zero data retention policy for open-model inference, prompts and generations are not logged to persistent storage by default; limited service metadata such as token counts may be retained. Fireworks states that it does not use prompts or API inputs to train models without explicit opt-in. See Fireworks data handling and trust.fireworks.ai.

We do not use Customer Content to train shared or public models. Outputs are AI-generated and require human review before use.

What happens when you run a document

  1. You upload process documents that describe how work happens today.
  2. 800 stores that material in the project database in the EU, scoped to your account, and reserves credits based on document size.
  3. During the run, extracted text is sent to Fireworks to produce an overview of tasks, agents, and humans, plus briefs.
  4. When the run finishes, credits are charged and you can export an overview for builders, vendors, or other agents.

Only upload documents you are allowed to share with a processor.

Subprocessors

These providers process data to deliver 800. When we add or replace a subprocessor that will process Customer Content, we aim to give at least 30 days' advance notice and a reasonable opportunity to object. Email legal@eight-hundred.app.

Credits and payments

Runs cost a fixed number of credits based on uploaded document size. You see the price before you start. Top-ups go through Stripe Checkout under Managed Payments. Credits are added only after Stripe confirms payment via a verified webhook. Credits do not expire, do not earn interest, and are not a bank deposit.

Access and operations

Production access is restricted to people who need it to operate 800, subject to technical access controls. Operational access is separate from the tenant-scoped project data shown in the product.

Retention and deletion

Projects can be deleted in the product. Account deletion and export: email legal@eight-hundred.app. Verification codes expire after 10 minutes. Deleted or closed accounts are cleared from active systems within 30 days of confirmation; backups within 90 days. Security logs are retained for 90 days. See the Privacy Notice for the full schedule.

Incidents and vulnerability disclosure

If you believe you found a security issue, email legal@eight-hundred.app. Include enough detail to reproduce the issue, and do not disclose vulnerabilities publicly until we have had a reasonable chance to fix them.

If we confirm a personal-data breach affecting Customer Content or Account Data, we will notify affected customers without undue delay.

Documents on request

  • Data Processing Addendum (GDPR Article 28): email legal@eight-hundred.app
  • Procurement or security questionnaire: same address

Related: Privacy · Terms · Home