Security Program
We operate a documented security program covering access control, encryption (in transit and at rest), vulnerability management, secure software development, incident response, and continuity. Security responsibilities are owned by named individuals; controls are reviewed and tested on a documented cadence.
Compliance Program
Our compliance program tracks GDPR, CCPA, and applicable U.S. state privacy laws. We maintain records of processing activities, data protection impact assessments for higher-risk processing, and a published Data Processing Addendum available to customers on request. Enterprise customers can request our current SOC 2 status and security questionnaire responses through their account team.
Privacy Practices
Our privacy practices are described in full in our Privacy Policy. In short: we collect only what is necessary, we do not sell personal data, we honor data subject rights, and we minimize the data we share with third parties.
AI Trust
Our AI Usage Policy describes how AI is used in the product, what it does not do, how customer data is handled, and what controls customers have. Enterprise customers can disable specific AI features, restrict model selection, and require human-in-the-loop approval for AI-suggested actions.
Subprocessors
A current list of subprocessors is maintained and available to customers. Material changes are announced before they take effect, giving customers time to object.
Incident Response and Disclosure
Security incidents that materially affect customer data are disclosed to affected customers without undue delay, in accordance with applicable law and contract. We publish post-incident summaries for incidents that warrant public disclosure.
Contact
Security inquiries: security@writingtoolspro.com. Privacy and data subject requests: privacy@writingtoolspro.com. Compliance documentation: compliance@writingtoolspro.com.