Security, privacy, and deployment — built into the delivery model.
GrowAppAI is designed for organizations that need role-based control, traceable changes, and deployment flexibility across SaaS, hybrid, and on-prem. This page summarizes our current posture and what is on the roadmap, so security and procurement teams can get answers before the first call.
Each item below is labeled by maturity so you can distinguish current capabilities from pilot and roadmap items.
Deployment that matches enterprise constraints
Different organizations have different security, privacy, and policy requirements. GrowAppAI is designed to run where your constraints require.
- SaaS deployment on infrastructure we operate.Available today
- Hybrid deployment combining centralized control with environment-specific execution boundaries.In pilot
- On-prem deployment for security-sensitive and regulated environments.In pilot
- Fully air-gapped installation packages.Roadmap
Access, roles, and organizational separation
- Role-based access control (RBAC) with admin roles.Available today
- Organization- and project-level access separation (multi-tenant isolation).Available today
- Enterprise SSO via SAML / OIDC.Roadmap
What we collect, store, and how it is removed
For website interactions, our Privacy Policy is the source of truth. For product data, handling is governed by your customer agreement and, where applicable, a Data Processing Agreement (DPA).
- Website form data (name, email, company, role) and attribution metadata, described in our Privacy Policy.Available today
- Deletion and data-access requests handled via privacy@growappai.com.Available today
- Configurable product data retention aligned to customer agreements.In pilot
- Customer-managed data residency options.Roadmap
How prompts, code, and models are handled
Because GrowAppAI works with source code and AI models, how that data flows matters. We are deliberately conservative about what we state here.
- Support for bringing your own model provider / API key.In pilot
- Prompt and output logging scoped to the owning organization for traceability.In pilot
- Local / self-hosted model execution for environments that cannot use external LLM providers.Roadmap
Traceability and exportable evidence
GrowAppAI treats auditability as a property of the workflow itself — connecting intent, stage outputs, actions, and delivery evidence.
- Action and stage-progression logging across the pipeline.Available today
- Release and CI evidence generation tied to pipeline runs.In pilot
- One-click audit evidence export bundles.Roadmap
Controls that protect data in transit and at rest
- Encryption in transit (TLS) for all web traffic.Available today
- Tenant isolation between organizations.Available today
- Centralized secret management for pipeline credentials.In pilot
- Documented backup and disaster-recovery objectives (RPO/RTO).Roadmap
Where we are heading on formal compliance
We do not claim certifications we do not hold. The items below are goals, not current attestations.
- SOC 2 Type II.Roadmap
- ISO/IEC 27001.Roadmap
- Data Processing Agreement (DPA) available on request for pilots.In pilot
- Alignment with SSDF / SLSA concepts in our governance messaging.Available today
Security contact
For security questions, contact security@growappai.com. To report a vulnerability, please follow our responsible disclosure policy.
Get our security overview for procurement
Tell us a little about your organization and we will share a security brief you can take into your review.
Continue the conversation
Explore how GrowAppAI fits your delivery model, governance priorities, and deployment requirements.