Security

Built for the people who audit everyone else

Teddy works with your most sensitive compliance data. It runs in the region you choose, is read-only by default, never trains AI models on customer data and records every action an agent takes, so you can show your auditor exactly what happened.

At a glance

How Teddy protects your data

Where your platform runs, and the principles that shape how Teddy and its agents work with your data.

Hosted in the region you choose

You decide where your Teddy platform runs, so your data stays where your policies and customers need it.

EUGermanyUS
Tenant isolation

Each customer’s data is logically separated. Agents only ever work inside your own workspace.

Encryption

Data is encrypted in transit and at rest. Credentials for connected systems are stored encrypted and never shown in the interface.

No training on your data

Teddy does not train AI models on customer data. Your controls, policies and evidence stay yours.

Read-only by default

Integrations use dedicated service accounts with read-only access. You approve the permission list before anything is connected.

Humans approve

Agents draft, people decide. Policies, risk acceptance and scope never change without a human approval.

Complete activity log

Every agent action, sync and approval is recorded with time and actor, ready to show your auditor.

Connecting your systems

How agents get access, and how you stay in control

Agents only see what you connect, with the permissions you approve.

1You approve the permissionsBefore a system is connected, you see and approve the exact permission list.
2Read-only service accountsAgents use dedicated service accounts with read-only access to collect evidence.
3Every action is loggedWhat an agent read, drafted or changed is recorded with source, version and time.
FAQ

Security questions, answered

Where is our data hosted?

You choose where your platform runs: in the EU, in Germany or in the US. We set up your workspace in the region you select.

Does Teddy train AI models on our data?

No. Teddy does not train AI models on customer data. Your controls, policies and evidence stay yours.

Can agents change our systems?

Connections are read-only by default, and you approve every permission before a system is connected. Approved documents can be written back, for example to Confluence.

Who approves what agents produce?

People. Agents collect, check and draft. Policies, risk acceptance, scope and anything that goes out need a named approval.

Can our auditor see what the agents did?

Yes. The activity log records every agent action, sync and approval with time and actor, and you can export it for your auditor.

Running a vendor review on Teddy?

Talk to the team about your security requirements, or see Teddy in a demo.