The entity you’re contracting with.
The short version. Full detail on the security page.
- Encryption in transit (TLS 1.2+) and at rest (AES-256) throughout.
- Multi-tenant isolation at database and API layer.
- MFA required for all admin/production access; enforced via identity provider.
- Zero-retention inference at Anthropic API — chats never used for model training.
- Audit logs retained 12 months; access to logs limited to founder + one contractor.
- Backups daily, geographically redundant within jurisdiction, tested quarterly.
- Incident response: 72-hour notification, 30-day post-incident report.
Full technical posture: /security · Trust & privacy overview: /trust
What we collect, why, how long we keep it.
Chat content is stored so users can access their history and so Projects retain context across sessions. Retained until the user deletes it. Not trained on. Not viewed by staff except during customer-requested support.
Account records (email, name, workspace membership) are retained for the duration of the account plus 7 years for finance-record purposes (billing reconciliation, tax audit trail). Deletable earlier on request per applicable privacy law (GDPR, CCPA, PIPEDA).
Payment data — card details never touch LADLE infrastructure; Stripe (PCI DSS Level 1) handles storage and processing. We store only a token to charge the card on file and the last-four for identification.
Full DPA: /legal/dpa · Subprocessor list: /legal/subprocessors
No trust marks we haven’t earned. No hidden gaps.
What your finance team gets.
- Payment methods: Credit card (default), ACH (US), wire (all), for orders ≥25 seats. Email partners@ladle.chat to switch off credit card.
- Invoice cadence: Monthly by default (cut on last calendar day of the month). Annual billing available at 10× monthly (two months free), invoiced on the anniversary of the first payment.
- Invoice format: PDF for records, CSV for line-item reconciliation. Itemized by seat, plan tier, and prorated adjustments.
- Tax handling: US sales tax collected where our nexus requires it. Canada GST/HST collected per federal + provincial rates. VAT for non-US/CA orders — reverse charge where applicable, our GST# on invoice.
- W-9 (US) / Business tax info: Available on request via legal@ladle.chat. Turnaround: one business day.
- Purchase orders: Accepted for orders ≥50 seats. Email partners@ladle.chat with PO terms.
- Sample invoice: Available on request; org name blanked, all other fields realistic.
12 answers your vendor-review form asks for. Paste them in.
Written to be copyable directly into the standard vendor-assessment questionnaires your organization uses. If a question isn’t here, email legal@ladle.chat — we’ll answer within one business day and add the question here if it’s one others will ask.
Where is our data stored?
In-transit and at-rest encryption throughout. Application data (chats, projects, account records) is stored in Supabase (AWS us-east-1). Inference is performed by Anthropic's API (AWS us-east-1 / us-west-2). Backups are geographically redundant within the same jurisdiction (US). No data-residency guarantee for EU or Canadian-only storage today; if this is a hard requirement for your organization, LADLE is not the right vendor at this time.
Is our data used to train models?
No. Chats are never used to train Anthropic's models — this is enforced via Anthropic's zero-retention API mode which LADLE uses for all inference. LADLE does not train models itself. This is contractually documented in the DPA at /legal/dpa (Data Processing Purposes section).
What is your incident response SLA?
Security incidents affecting customer data are notified within 72 hours of confirmed detection, per GDPR-aligned practice. Post-incident report delivered within 30 days including root cause, affected data categories, remediation, and prevention. Non-security service incidents are posted to /status in real time.
What is the process for our organization's data deletion?
Two paths. (1) Individual user deletion: Settings → Delete account triggers full deletion within 30 days across primary and backup systems. (2) Organization-wide deletion at contract termination: email legal@ladle.chat with the request; deletion completes within 30 days and a written confirmation is provided. Anonymized audit-log entries (billing reconciliation) are retained per finance-record requirements (7 years, jurisdiction-dependent).
Do you have a Data Processing Addendum (DPA)?
Yes. Executable DPA at /legal/dpa covers scope of processing, subprocessors, security measures, breach notification, deletion, international transfer terms (Standard Contractual Clauses annexed), and audit rights. Draft-status footer notes the document is subject to counsel review before enterprise execution; for negotiated terms, email legal@ladle.chat.
Who are your subprocessors and how are we notified of changes?
Current list at /legal/subprocessors, versioned and dated. Notification of new subprocessors: 30 days advance notice via email to the workspace's designated privacy contact, plus RSS-style changelog on the subprocessors page. Right to object to a new subprocessor is documented in the DPA.
What insurance do you carry?
General liability and cyber liability coverage in place. Cyber-specific limits and carrier available on request via legal@ladle.chat (not published publicly to avoid disclosing coverage limits). We are a small company; our insurance posture is appropriate for our scale and will scale with revenue.
Can we get invoice samples for our finance team's review?
Yes. Email partners@ladle.chat with your organization name and preferred format; we send a sample invoice (org name blanked, all other fields realistic) within one business day.
What is your uptime SLA?
99.5% target for the LADLE application, measured over calendar month. Uptime history at /status. If a customer's usage is materially affected by an outage below the 99.5% threshold in a given month, a pro-rata service credit is available on request (not automatic; email support@ladle.chat with the outage window).
What's your business continuity plan?
Data is backed up daily to a geographically redundant secondary region. Recovery time objective (RTO) is 24 hours for application availability; recovery point objective (RPO) is 24 hours for user data. Full BCP document available on request via legal@ladle.chat under NDA.
How do you handle employee access to customer data?
Principle of least privilege. Only two people at LADLE (founder and one contractor) have production access; both are covered by written confidentiality agreements. Production access is logged. Customer chat content is not viewed by staff except in the case of an explicit customer-requested support incident where the customer authorizes it.
What happens if LADLE is acquired or shuts down?
In an acquisition, customer contracts (including DPA terms) transfer to the acquirer under the same terms. In a shutdown, we commit to 90 days advance notice, full data export tooling (already available), and open-source publication of critical technical documentation (data schema, subprocessor list) so any migration can proceed. Legal terms detailed in /legal/terms.
No forms, no gatekeepers. Direct emails.
One-business-day reply on all channels. No auto-responders, no ticket queues. If your question needs a live conversation, we schedule a 30-minute call — no slides, no demos-with-a-quota.
Everything else your procurement team needs is one email away.
Written for procurement, answered by LADLE PBC. We prefer real conversations.