Skip to main content
Bower is built for researchers who handle sensitive data. Every feature, from capture to AI processing, is designed with security, privacy, and data isolation as defaults, not afterthoughts.

Compliance

GDPR

GDPR

Compliant

SOC 2 Type I

SOC 2 Type I

Final stages

SOC 2 Type II

SOC 2 Type II

Observation window

HIPAA

HIPAA

Final stages

Australian Privacy Act

Privacy Act (AU)

Compliant

WCAG 2.2 Level AA

WCAG 2.2 AA

In progress

Bower is under independent audit with Advantage Partners for SOC 2 Type I, SOC 2 Type II, and the HIPAA Security Rule. No report has been issued yet, so Bower is not yet SOC 2 attested; we will publish each one here as it lands, available under NDA. If you need control documentation, a DPA, or a BAA in the meantime, email [email protected].

Security overview

AES-256 encryption

All data encrypted at rest using AES-256 and in transit via TLS, on every connection.

Workspace isolation

Each workspace’s data is isolated at the data layer, scoped to a single workspace beneath the application so cross-workspace access is blocked before any data is returned.

Audit logging

Every create, update, and delete action is logged with who, what, when, and field-level diffs. Exportable to CSV.

Session management

30-minute inactivity timeout. Revoke all sessions instantly from settings. Token expiry enforced server-side.

Role-based access

Four roles (Owner, Admin, Member, Guest) with strict hierarchy enforced at the API level.

AI data handling

We do not use your identifiable content to train AI models, and our providers are contractually barred from training on it too.

Compliance & data protection

GDPR compliant

Full data subject rights: export, deletion, and portability. Designated Data Protection Officer. 30-day response SLA on all requests.

Australian Privacy Act

Operated by Benenota Pty Ltd (ABN 60 691 836 085), compliant with the Australian Privacy Principles (APPs).

Accessibility

We build to WCAG 2.2 Level AA. Our statement covers what we target, the gaps we know about, and how to report a barrier.

Report a vulnerability

Found a security issue? Email us and we will acknowledge within one business day. We do not pursue good-faith researchers.

Your data rights

  • Export: download a complete copy of all your personal data as JSON from Settings > Security > Export my data
  • Delete: permanently remove your account and all associated data from Settings > Security > Danger Zone
  • Cookie control: choose exactly which cookies Bower uses, changeable at any time from Settings > Security
  • DPO contact: reach our Data Protection Officer at [email protected]

Infrastructure & sub-processors

All primary data is hosted on Google Cloud Platform (us-central1). The summary below covers our main infrastructure and AI providers. See the complete sub-processor list for every provider, the data it processes, and its current DPA or BAA status. Restricted mode is a separate HIPAA control: it blocks protected content from providers without a signed BAA.
Your content is sent to these providers to produce a result. We do not use your identifiable content to train AI models, and our providers are contractually barred from training on it. See AI & your data.
Sub-processor list reviewed quarterly. Last reviewed: August 2026. View full list →

Policies & documentation

Data privacy

The full technical breakdown of encryption, workspace isolation, access controls, deletion, and your data rights.

Sub-processors

Complete list of third-party services that process data on behalf of Bower, with current DPA and BAA status.

Cookie policy

What cookies Bower uses, why, and how to control them. Essential vs. analytics categories.

Audit logs

Track every change in your workspace: who did what, when, with field-level diffs.

Password & security

Manage your password, sign-in methods, sessions, and account security settings.

Privacy Policy

How we collect, use, store, and protect your personal information. Published on bowerlabs.ai.

Terms of Service

Terms governing your use of Bower, including what we may and may not do with your data. Published on bowerlabs.ai.

Accessibility statement

Our WCAG 2.2 Level AA target, the gaps we know about, and how to report an accessibility barrier.

Questions?

If you have security questions, need a DPA, or want to report a vulnerability, contact us: Trust Center last updated: August 2026.