Compliance
GDPR
Compliant
SOC 2 Type I
Final stages
SOC 2 Type II
Observation window
HIPAA
Final stages
Privacy Act (AU)
Compliant
WCAG 2.2 AA
In progress
Security overview
AES-256 encryption
All data encrypted at rest using AES-256 and in transit via TLS, on every connection.
Workspace isolation
Each workspace’s data is isolated at the data layer, scoped to a single workspace beneath the application so cross-workspace access is blocked before any data is returned.
Audit logging
Every create, update, and delete action is logged with who, what, when, and field-level diffs. Exportable to CSV.
Session management
30-minute inactivity timeout. Revoke all sessions instantly from settings. Token expiry enforced server-side.
Role-based access
Four roles (Owner, Admin, Member, Guest) with strict hierarchy enforced at the API level.
AI data handling
We do not use your identifiable content to train AI models, and our providers are contractually barred from training on it too.
Compliance & data protection
GDPR compliant
Full data subject rights: export, deletion, and portability. Designated Data Protection Officer. 30-day response SLA on all requests.
Australian Privacy Act
Operated by Benenota Pty Ltd (ABN 60 691 836 085), compliant with the Australian Privacy Principles (APPs).
Accessibility
We build to WCAG 2.2 Level AA. Our statement covers what we target, the gaps we know about, and how to report a barrier.
Report a vulnerability
Found a security issue? Email us and we will acknowledge within one business day. We do not pursue good-faith researchers.
Your data rights
- Export: download a complete copy of all your personal data as JSON from Settings > Security > Export my data
- Delete: permanently remove your account and all associated data from Settings > Security > Danger Zone
- Cookie control: choose exactly which cookies Bower uses, changeable at any time from Settings > Security
- DPO contact: reach our Data Protection Officer at [email protected]
Infrastructure & sub-processors
All primary data is hosted on Google Cloud Platform (us-central1). The summary below covers our main infrastructure and AI providers. See the complete sub-processor list for every provider, the data it processes, and its current DPA or BAA status. Restricted mode is a separate HIPAA control: it blocks protected content from providers without a signed BAA.Infrastructure & hosting
Infrastructure & hosting
AI processing
AI processing
Your content is sent to these providers to produce a result. We do not use your identifiable content to train AI models, and our providers are contractually barred from training on it. See AI & your data.
Policies & documentation
Data privacy
The full technical breakdown of encryption, workspace isolation, access controls, deletion, and your data rights.
Sub-processors
Complete list of third-party services that process data on behalf of Bower, with current DPA and BAA status.
Cookie policy
What cookies Bower uses, why, and how to control them. Essential vs. analytics categories.
Audit logs
Track every change in your workspace: who did what, when, with field-level diffs.
Password & security
Manage your password, sign-in methods, sessions, and account security settings.
Privacy Policy
How we collect, use, store, and protect your personal information. Published on bowerlabs.ai.
Terms of Service
Terms governing your use of Bower, including what we may and may not do with your data. Published on bowerlabs.ai.
Accessibility statement
Our WCAG 2.2 Level AA target, the gaps we know about, and how to report an accessibility barrier.
Questions?
If you have security questions, need a DPA, or want to report a vulnerability, contact us:- Security & vulnerability reports: [email protected]
- Data Protection Officer: [email protected]
- Accessibility feedback: [email protected]
- General support: [email protected]