Security & data handling

Last updated: September 22, 2026. How Codebeatz Technologies Inc. protects data in Fractionalyse.

1. What this page covers

This page describes how Codebeatz Technologies Inc. protects data in Fractionalyse. It is written so you can forward it to a client’s IT or security team when you ask for workspace access.

It covers current connections, token handling, isolation, AI processing, retention, and the service providers that process data to run the product. The Privacy Policy explains collection and rights. The Terms of Service are the contract. This page is an operational description. It is not a certification, audit report, or a separate warranty unless we sign a written DPA or other agreement.

The public demo uses fictional sample data and does not connect your tools. Roadmap tools named in marketing (for example Microsoft Teams) are not connected until we ship them. If we add a connection or change who processes prompts in production, we will update this page.

2. Access we request

Each connection is bound to one client that you choose. We use it only to read activity for that client. The product does not post, send, edit, create, complete, transition, comment, or delete in Slack, Asana, Jira, or Notion on your behalf. Disconnecting a connection does not change data that remains in the third-party tool.

Slack, as yourself: a user token, with no workspace-wide install. We poll conversations that token can already see. Granted access is conversation history and directory reads (member names, and email addresses where users:read.email is granted). There is no permission to post messages or administer the workspace.

Slack, workspace app: the Events API, for real-time delivery. A client admin may need to approve the install. Granted access is conversation history for channels the app is in, plus the same directory reads. There is no permission to post messages or administer the workspace. Incoming Slack events are signature-checked, including a short replay window.

Email bridge: there is no mailbox connection. We receive only messages you or your client forward to the inbound address we issue for that client. That works with Gmail, Outlook, and other mail providers. Inbound mail notifications are signature-checked. Google sign-in, if you use it, is for account authentication only. We do not offer native Gmail inbox access.

Asana: tasks assigned to you, including name, notes, and due date. The product only reads those tasks. It does not create, complete, or edit them.

Jira Cloud: issues assigned to you on the site you authorize, including summary, description, status, and due dates. The grant is read access to Jira work and users, plus a refresh token so the connection can stay signed in. There is no permission to create, transition, or comment on issues.

Notion: only pages you select during connect, with read-content access. The product does not create or edit Notion pages.

3. How data is protected

Connection tokens are encrypted at rest with AES-256-GCM and a versioned key, so keys can be rotated. Tokens are excluded from columns the browser can read, and they are not written to application logs.

Each client’s rows are bound to the owning account in the database (row-level security), not only in application code. A signed-in browser session cannot read another account’s clients, tokens, feed, or Client Memory.

Background workers run on the server. They are authenticated and are not callable from the browser. The privileged database credential used by those workers is not shipped to the browser.

Connect flows use a signed, short-lived state value so a callback cannot be attached to a different account. Incoming Slack events, inbound email notifications, and payment webhooks (when billing is enabled) are signature-checked. Duplicate deliveries are ignored.

Traffic to the application is encrypted in transit. Public traffic is fronted by Azure Front Door, including a web application firewall and rate limits on public routes.

Error monitoring is configured not to send default personal data. It is used to diagnose failures. It is not a store of client workspace content. If we become aware of a breach affecting personal information, we will notify you and regulators as required by applicable law. Reports: security@fractionalyse.com.

4. Client isolation

You decide which client workspaces to create and which tools to connect to each one. Data from two clients is not combined in the feed, in a prompt, in search, or in an Ask session.

Search and Ask stay inside the client you selected. A result from one engagement is not returned as context for another.

5. AI processing

Production urgency scores, summaries, Catch Me Up digests, Client Memory answers, and embeddings are processed by Azure OpenAI in Canada. Each request is scoped to a single client’s activity.

Embeddings are used only to index and retrieve that client’s Client Memory.

We do not train our own foundation models on your content, and we do not sell your content for model training. The AI provider processes prompts and completions under its terms. If the production AI provider changes, we will update this page.

AI output can be incomplete or incorrect. It is an aid for triage and recall. Verify important items in the source system before you act.

6. Client Memory

Non-noise activity may be indexed into a durable per-client knowledge store so you can search and ask about prior context after the live feed ages out. Those documents and chunks stay bound to the same account and client as the rest of the product.

Access to search and Ask depends on your plan, as described on the pricing page and in the Privacy Policy. When a temporary Memory window ends, search, Ask, and new embedding are unavailable. Stored knowledge is kept until you purge the connection or delete the client, unless we must delete it sooner for legal or security reasons.

Disconnect & purge removes the token and the ingested items for that connection, including related Client Memory documents and chunks. Deleting a client removes feed items, digests, and Client Memory for that engagement.

7. Retention and deletion

Feed items are retained for 90 days by default, then deleted, unless a longer period is required for security, billing, dispute, or legal reasons. Client Memory is retained until you delete the client or purge the connection, so durable context can outlive the feed window.

You can disconnect an integration and purge ingested data for that connection, or delete a client workspace, from the product. Deleting your account removes the profile, client workspaces, connections, tokens, feed items, digests, and Client Memory from the live service at that time. There is no in-app export. If you need a copy, request it before you delete the account.

Invoices stay with our payment provider for tax, accounting, and disputes. Copies in encrypted backups remain until those backups rotate. If a deletion cannot be completed (for example a legal hold), we keep only what we must.

We can pause background processing or place the service in maintenance to contain an incident. That can make some or all of the product unavailable until the measure is lifted.

8. Subprocessors and location

These providers process data to run the Service, under their terms and, where applicable, a contract:

Microsoft Azure App Service (Canada Central) hosts the application. Microsoft Azure Front Door provides the edge and web application firewall. Microsoft Azure OpenAI processes production prompts, completions, and embeddings in Canada.

Supabase provides the production database, sign-in, and realtime updates, in Canada, in the same region as the application. Row-level security is enforced in that database.

Resend delivers outbound product email and receives the inbound email bridge, including message content that is forwarded to a client’s inbound address.

Stripe processes subscription billing when checkout is enabled. We do not store full card numbers on our servers.

Sentry receives application error reports, configured not to send default personal data. Better Stack checks public health URLs only. Those uptime checks do not receive client workspace content.

Slack, Asana, Atlassian (Jira), Notion, and your email provider process data under their own terms when you authorize a connection or forward mail.

Resend, Stripe, Sentry, Better Stack, and the tools you connect may process information in the United States or other countries. Primary application hosting and production AI processing are in Canada.

9. Limits of this page

No method of transmission or storage is perfectly secure. We do not claim a SOC 2 report, an ISO certificate, or a completed third-party penetration test on this page.

Controls described here can change as we operate the product. Material changes will be reflected with an updated date on this page. Questions, DPA requests, or security reports: security@fractionalyse.com.

Questions, DPA requests, or security reports: security@fractionalyse.com