# Trust Center

Cactus's SOC 2 status, the security controls in place today, and the companies that handle your data.

Cactus is built on SOC 2's criteria and on least privilege. Every fact below was checked against its code and systems on September 26, 2026.

## Built on SOC 2's criteria

| SOC 2 | Status | What it means |
| --- | --- | --- |
| In place today | 47 controls | Each one answers a SOC 2 criterion and is listed below with it. |
| SOC 2 Type I | Being prepared | An independent auditor's report on how the controls are designed. |
| SOC 2 Type II | Being prepared | The same auditor's report on how the controls work over a period of months. |

Access follows least privilege: the GitHub App can only read your code, the sandbox that searches it can only read the copies, and only a team's Owners can invite or remove people.

A SOC 2 report comes from an independent auditor who has tested a company's controls.

If your review needs something this page does not answer, write to [hello@heycactus.ai](mailto:hello@heycactus.ai).

## Security (CC1 to CC9)

Who can reach Cactus and your data, and how.

| Control | Criteria | What Cactus does |
| --- | --- | --- |
| Sign-in | CC6.1 | People sign in with Google or GitHub, and Cactus never asks for a password and stores none. |
| Session cookie | CC6.1 | A signed-in session is a cookie that page scripts cannot read, that travels only over HTTPS, and that is set only for the app's own address, so no Help Center ever receives it. |
| Session end | CC6.1 | A session lapses after a week without use, and signing out deletes it on the server. |
| Roles | CC6.2, CC6.3 | Only a team's Owners can invite or remove people, change someone's role, create, rebuild or delete a product, or add a custom domain, and the server checks the role on each of those requests. |
| Removing someone | CC6.2 | When an Owner removes someone, their access to the team's data ends on their next request, in the app and in every AI client they connected. |
| GitHub App | CC6.3 | The GitHub App can read code and list repositories and nothing more, so it cannot push a commit, open a pull request or change a setting. |
| AI-client sign-in | CC6.1 | An AI client's access token lasts an hour, and Cactus stores every AI-client token only as a hash, never the token itself. |
| Two-factor sign-in | CC6.1 | Everyone in Cactus's GitHub organization, where its code lives, must use two-factor authentication. |
| The server's network | CC6.6 | The server where Cactus's agents run has no public address: it opens its own connection to Cactus's Restate environment and runs only the requests that environment has signed. |
| Signed messages | CC6.6 | Messages from GitHub, Slack and Discord are checked against the sender's signature and refused when it does not match, and Slack's and Discord's are refused once they are five minutes old. |
| Requests from other sites | CC6.6 | The app's server functions refuse a request that another website sends on a signed-in person's behalf. |
| Limits | CC6.6 | A visitor can ask one product 30 questions an hour, and an AI client that has not signed in can make 60 calls to a product every five minutes. |
| Encryption in transit | CC6.7 | Every address under heycactus.ai answers only over HTTPS, with TLS 1.2 or newer, and sends a plain HTTP request on to HTTPS. |
| Browser protections | CC6.6, CC6.7 | The website, the app and every Help Center under heycactus.ai tell browsers to use only HTTPS with them for a year and never to guess a file's type, and no other site may frame the website or the app. |
| Database connections | CC6.7 | Every connection to the database is encrypted, because Neon, which runs it, refuses any connection that is not. |
| Encryption at rest | CC6.1 | The database, the live updates and the copies of your code are encrypted at rest by Neon, Convex and Modal, the companies that store them. |
| Tokens for your accounts | CC6.1 | Cactus encrypts the tokens it holds for your Slack workspace and your Intercom account with AES-256-GCM before it stores them, and every sign-in with Google or GitHub stores the tokens they hand over encrypted too. |
| GitHub install tokens | CC6.1 | Copying or updating your repository never writes GitHub's install token to a file: the copy points at the repository's public address, and the token reaches git only through its environment, for that one command. |
| Cactus's own keys | CC6.1 | The keys Cactus's own services run with are stored as encrypted secrets on Cloudflare, Azure and Modal. |
| Logging | CC7.2 | Every request to the website, the app, the Help Centers, the Messenger and the AI-client server is logged, and errors in browsers, the app and the server are reported to Cactus's error tracking. |
| Changes | CC8.1 | Every change since September 12, 2026 has reached Cactus's code as a pull request, and every pull request runs the type checks, unused-code checks and tests of each part of Cactus. |
| Deploys | CC8.1 | Cactus's pipeline deploys the website, the app, the Messenger and the AI-client server only from main, and only after every check has passed on that commit. |
| Dependencies | CC8.1 | The pipeline installs dependencies at the exact versions in the lockfile, and fails rather than change it. |
| Reporting a problem | CC2.3 | Anyone can report a security problem to [hello@heycactus.ai](mailto:hello@heycactus.ai) without an account, and the address is also in heycactus.ai's [security.txt](/.well-known/security.txt), where security tools look for it. |

## Availability (A1)

Cactus being there when you and your customers need it.

| Control | Criteria | What Cactus does |
| --- | --- | --- |
| Where it runs | A1.2 | The website, the app and every Help Center run on Cloudflare's network, from its data centers around the world. |
| Interrupted jobs | A1.2 | Cactus's jobs run on Restate, which records each step as it finishes, so a job interrupted by a restart or a failure picks up at the step it was on. |
| Database history | A1.2 | Neon keeps up to six hours of the database's history, from which a copy of the database as it stood at an earlier moment can be made. |
| Copies of your code | A1.2 | The copies of your repositories and the search index are made from GitHub, so a lost copy is made again from there. |

## Confidentiality (C1)

Keeping what you share with Cactus to the people it is for.

| Control | Criteria | What Cactus does |
| --- | --- | --- |
| What visitors see | C1.1 | Your Help Center, its address for AI clients and the Messenger show a visitor only pages set to Everyone that Cactus has also written for readers outside your team. |
| Code in answers | C1.1 | An answer to a visitor never lists a file of your code among its sources, and the lines of code behind a page are shown only to your team. |
| Only you | C1.1 | A page set to Only you is shown only to the person who set it, and only they can change who it is for. |
| Team only | C1.1 | With the Help Center set to Team only, it and its address for AI clients answer anyone outside your team as if there were no Help Center. |
| The sandbox | C1.1 | Commands that read your code run on Modal in a sandbox with no network and no keys in it, which can read the stored copies but not change them. |
| The server's disk | C1.1 | The server where Cactus's agents run reads your files through that sandbox or from GitHub, and never writes your code to its own disk. |
| Traces | C1.1, CC7.2 | Model calls are traced for debugging and quality, and only Cactus's two founders can open the traces, which they do only to debug. |
| Secrets in your code | C1.1 | Before your code is indexed for search, gitleaks scans it, every line where it finds a key or a password is blanked, and the secret itself is never logged. |
| Secrets in Slack | C1.1 | Keys and database connection strings of the common kinds pasted into Slack are replaced with [secret] before the messages are stored. |
| Deleting a product | C1.2 | Deleting a product deletes its pages, conversations, sources and settings from the database in one step, and its copies of your code on Modal. |

## Processing integrity (PI1)

Pages and answers that match the code they describe.

| Control | Criteria | What Cactus does |
| --- | --- | --- |
| Pushes | PI1.2 | A page is rewritten from a push only after GitHub's signature on that push checks out. |
| Cited code | PI1.4 | Each section of a page records the repository, commit, file and lines it rests on, and quotes those lines, so your team can check it against the code. |
| Page history | PI1.5 | A section that changes is saved as a new version, and the old one is kept, not overwritten. |

## Privacy (P1 to P8)

What happens to personal information, and when it goes.

| Control | Criteria | What Cactus does |
| --- | --- | --- |
| Notice | P1.1 | What Cactus collects, what it uses it for, how long it keeps it and who else receives it is written on the [Privacy page](/privacy). |
| Model training | P4.1 | Cactus trains no model on your code or on anything else it reads. |
| Model providers | P4.1 | OpenAI says it does not train on data sent through its API and TypeSafe AI's privacy policy says the same, while the Vercel AI Gateway, which carries every call, says it neither uses prompts or responses for training nor retains them. |
| No-training setting | P4.1 | Every model call Cactus makes, its search embeddings included, asks the gateway to send it only to providers that do not train on prompts, and fails rather than go to one that does. |
| Slack messages | P4.2 | Slack messages are deleted once no message in their thread has changed for 90 days. |
| Job records | P4.2 | Restate deletes each job's record of its steps, which can hold the files the job read, within seven days of the job ending. |

## The companies that handle your data

What each one does for Cactus, what it receives, and where, when that is settled. Privacy and the Data Processing Addendum list the same companies.

| Company | Where | What it does and receives |
| --- | --- | --- |
| Cloudflare | Worldwide (Cloudflare's network) | Cloudflare runs the website, the app and every Help Center, and keeps a log of each request. |
| Microsoft Azure | United States (East US 2, Virginia) | Microsoft Azure runs the server where Cactus reads your sources and writes pages and answers. |
| Restate | United States (AWS us-east-2, Ohio) | Restate runs Cactus's jobs, and keeps a record of each job's steps, including what each step read, for seven days. |
| Neon | United States (AWS us-east-1, Virginia) | Neon stores the database, including the search index of your code. |
| Convex |  | Convex carries live updates, including the words of an answer while it is being written. |
| Modal | United States for stored copies; the sandboxes can run in any region Modal uses | Modal copies your repositories, builds the search index of your code, and runs the commands Cactus reads it with. |
| Vercel |  | The Vercel AI Gateway carries every call Cactus makes to a model. |
| OpenAI |  | OpenAI runs the models that read your sources and write pages and answers, and the model that turns text into search vectors. |
| TypeSafe AI |  | TypeSafe AI runs Jev, the model that makes some small decisions, such as whether your customers would notice a release. |
| Firecrawl |  | Firecrawl reads your product's public website, to find its logo, its colours and its links, and fetches a public page for Cactus when a site turns a plain request away. |
| Resend | United States | Resend sends our email, including the email your customers get when they write to your team. |
| PostHog | United States (AWS us-east-1, Virginia) | PostHog records usage events, errors and recordings of visits to the app and to Help Centers, and keeps traces of model calls for debugging, which only Cactus's two founders can open. |
| Google and logo.dev |  | Google and logo.dev supply the small logo shown beside a product's name. The browser asks them for it by the product's web address. |
| Google and GitHub |  | Google and GitHub sign you in, when you choose to sign in with them. |

## What Cactus reads from GitHub

Cactus reads code through its GitHub App, Cactus Product Cataloger. The app sees the repositories you give it at install, and Cactus reads only the ones you add to a product.

- The list of repositories the app can see, with each one's name, language and default branch.
- The newest commit on the branch a product follows, and the files in it.
- Commit messages, their times and their authors' names, which Cactus reads to write What's New.

When you push, GitHub tells Cactus, and Cactus reads the new commit. A message whose GitHub signature does not match is turned away.

At install, GitHub hands Cactus a token that says who you are. Cactus uses it once, to check which installations are yours, and does not keep it.

Cactus cannot write to your repositories: the app has read access only, so it cannot make a commit, open a pull request or change a setting.

## What the GitHub App may do

GitHub shows these permissions at install. Here is the whole list, as GitHub reported it on September 26, 2026, and what Cactus does with each, on the repositories you give it:

| Permission | Access | What Cactus does |
| --- | --- | --- |
| Contents | Read | Reads your files and commits. |
| Metadata | Read | Lists the repositories you gave the app. |

The app asks for nothing on your organization or on your GitHub account.

Push is the one event the app asks GitHub for:

| Event | What Cactus does |
| --- | --- |
| Push | Reads the new commit. |

## Where your code goes

Cactus copies each repository you add to a product onto Modal, a cloud computing service, into a folder for that product. Each time it makes or updates a copy, it asks GitHub for a new token.

Cactus searches your code with git and ripgrep, on Modal too, in a sandbox with no network that can read the copies but not change them. A sandbox stops after 15 idle minutes, and after 30 at most.

The server where Cactus's agents run, on Microsoft Azure, reads your files through that sandbox or from GitHub, and never writes your code to its own disk.

Deleting a product deletes its copies on Modal. If that fails, the next index run of any product removes them.

## Who can see what

People sign in with Google or GitHub. Cactus keeps no passwords.

Everyone on a team can read the team's pages, its conversations and the map of its code, and can connect sources. Only an Owner can invite or remove people, change someone's role, or delete a product.

Each page is set to Only you, Your team or Everyone. Your Help Center, its address for AI clients and the Messenger show a visitor only the pages set to Everyone that Cactus has also written for readers outside your team.

Set the Help Center to Team only, and it and its address for AI clients answer anyone outside your team as if there were none.

An answer to a visitor never lists a file of your code among its sources. The lines of code behind a page are shown only to your team.

## How models are called

Cactus calls every model through the Vercel AI Gateway.

- Pages and answers are written by OpenAI's gpt-6-luna, and each of those calls tells the gateway to send it to OpenAI and nobody else.
- Search uses OpenAI's text-embedding-3-small, which turns text into search vectors.
- Some small decisions, such as whether your customers would notice a release, are made by Jev, a model from TypeSafe AI.

Cactus does not train models on your code.

## Report a security problem

Write to [hello@heycactus.ai](mailto:hello@heycactus.ai) with any security problem you find in Cactus and how to see it again. You do not need an account.

The same address is in [heycactus.ai/.well-known/security.txt](/.well-known/security.txt), the file security tools read to find where to report.

What Cactus collects, how long it keeps it, and the companies that run parts of it are on the [privacy page](/privacy).
