Envelope

Trust & Security

Last updated: 26 June 2026

We never train on your data.

Your team designs, agent prompts, credentials, and workspace content are yours. They are never used to train models, improve Envelope's AI features, or shared with third parties for any purpose other than delivering the Service to you.


Your data

Envelope stores the following categories of data on your behalf:

  • Account data — email address, name, and avatar from your sign-in provider
  • Design workspace data — agent configurations, roles, prompts, tool access policies, and team specs you create
  • Credentials — API keys and secrets stored in the credentials vault, encrypted at rest
  • Billing data — subscription status and invoice history (card details handled exclusively by Stripe)

You can request export or deletion of your data at any time by emailing [email protected]. Enterprise customers can request a DPA — see /dpa.


Encryption

  • At rest — credentials stored in the vault are encrypted using AES-256 before being written to the database. Encryption keys are stored separately from encrypted data.
  • In transit — all communication between your browser, the Envelope API, and third-party services uses TLS 1.2 or higher. We do not support unencrypted HTTP in production.
  • Database — the underlying PostgreSQL database uses encryption at rest provided by the hosting infrastructure.

Hosting & infrastructure

Envelope is currently hosted in the United States (us-east-1). The API server and PostgreSQL database run on managed cloud infrastructure. We do not operate our own physical hardware.

If you require data to be hosted in a specific region, or need a private cloud deployment, please contact us — regional options and BYOC (Bring Your Own Cloud) are on our roadmap for enterprise customers.


Authentication

Envelope supports three sign-in methods:

  • Magic link — a one-time sign-in link sent to your email via Resend. Links expire after 15 minutes and can only be used once.
  • GitHub OAuth — sign in with your GitHub account. We request read-only access to your profile and email only.
  • Google OAuth — sign in with your Google account. We request your name and email only.

Envelope does not store passwords. Session tokens are cryptographically signed and expire after 30 days of inactivity.


Payments

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. Envelope never receives, sees, or stores full card numbers. Stripe returns only a tokenised representation of your payment method, which we store for subscription management purposes.


Analytics

Envelope uses Plausible Analytics to understand site traffic. Plausible is a privacy-friendly analytics tool — it sets no cookies, collects no personal data, and is fully GDPR, CCPA, and PECR compliant. No consent banner is required. You can view Plausible's data policy at plausible.io/privacy.


Sub-processors

We use the following third-party sub-processors to deliver the Service:

| Provider | Purpose | Location | |---|---|---| | Replit | Hosting, compute, database | United States | | Stripe | Payment processing | United States | | Resend | Transactional email (magic links) | United States | | GitHub | OAuth sign-in (optional) | United States | | Google | OAuth sign-in (optional) | United States | | Plausible | Privacy-friendly analytics | European Union |


Responsible disclosure

If you discover a security vulnerability in Envelope, please report it to us privately before disclosing it publicly. Email [email protected] with a description of the issue and steps to reproduce it.

We will acknowledge your report within 2 business days and aim to resolve confirmed vulnerabilities within 30 days. We will not take legal action against researchers who report issues in good faith.


Contact

For any security or privacy questions, email [email protected]. For a signed Data Processing Agreement, see /dpa.