Your systems
The CRM, inbox, and data you connect. Go Fig only reads unless you turn writing on.
Security
See exactly what Go Fig can read, what it stores, and what it never touches. Every safeguard your security team will ask about is on this page.
How your data moves
Here's what happens when you ask Go Fig a question.
The CRM, inbox, and data you connect. Go Fig only reads unless you turn writing on.
Every request is checked so it only touches your company's data.
Only what the question needs goes out. Emails, phone numbers, card numbers, and Social Security numbers are removed first.
We only use their business plans. Their terms say your data never trains their AI.
Personal details are removed again on the way back, and the whole exchange is logged.
The controls
Celeste, Go Fig's AI analyst, can look at your data to answer a question. She can't change or delete anything.
Every write is logged. Every change Go Fig makes in your tools is recorded in a log your team can review.
How writing back worksEmail addresses, phone numbers, Social Security numbers, and credit card numbers are removed before anything reaches an AI provider. They're removed again before you see a response.
Example of what the AI sees
Every conversation with the AI is logged on every plan, so you can always see which data Celeste used.
Which deals went quiet this month?
Tables: deals, contacts
Four protect your data when AI looks things up. Four protect it everywhere else.
When AI looks up data
Everywhere else
For your security team
Open any section for the full detail your security team will want.
What Go Fig can change
Writing back means Go Fig making a change in one of your tools, like updating a CRM record or sending an email. An admin turns it on for your company, then for each tool. A personal inbox or CRM login also needs its owner's OK. No plan turns it on for you. Every change Go Fig makes in your tools is recorded in a log your team can review.
Once an admin turns it on, these are the kinds of changes Go Fig can make in the tools you connect.
| Capability | Example |
|---|---|
| Accounting | Create invoices, bills, journal entries, estimates, customers, and vendors in QuickBooks |
| Send through a connected Gmail or Outlook mailbox | |
| Messaging | Post to Slack |
| Productivity | Write to Notion, create calendar events, update CRM records |
Your plan decides which tools you can connect, so it also limits where Go Fig could make changes. Think twice before turning this on for a tool that emails customers or holds your official records.
AI providers
In short, the AI sees your question, the names of your fields, and at most 100 example records you're allowed to see. It never sees passwords, other companies' data, or fields you can't see. The full detail for your security team is below.
The AI companies we use have agreed not to learn from your data. We only use their paid business plans (business API tiers), and their standard terms say data sent this way isn't used for training. We never use their consumer apps, and we never train (fine-tune) a model on customer data. A backup provider answers when the main one can't.
| Provider | Role | Training |
|---|---|---|
| Google, Gemini via Vertex AI | Main provider, every plan | Not used for training, under Google Cloud's data terms |
| OpenAI, GPT | Backup and some specific tasks, every plan | Doesn't train on data sent through its API |
| Anthropic, Claude | Backup on some plans. Starter sends no data to Anthropic | Doesn't train on data sent through its API |
To answer a question, the AI needs to know what you asked and what your data looks like. It gets small, capped samples, never your whole database. Go Fig uses your field names and types to write a query (the request that pulls the right data).
| Sent | Why |
|---|---|
| Your question and the conversation so far | To understand what you're asking |
| Table names, field names, and field types | To write an accurate query |
| How your team defines its metrics | To use your company's own terms |
| A few example values, with personal details removed | To see what the data looks like |
| Up to 100 example rows from a relevant table | To base the answer on your real data |
| Query results, cut to a set size | To explain the result in words |
Example rows and results are filtered by your role first. A field that's hidden or masked for you is left out of what gets sent. Your logins to your tools are never sent either.
| Never sent | How |
|---|---|
| Whole tables or bulk exports | Only small, capped samples are sent |
| Passwords, API keys, OAuth tokens | Never included in anything sent |
| Other companies' data | Walled off by tenant isolation |
| Fields your role can't see | Removed before anything is sent |
Three more places your data is used, each with its own limits.
Search index. Go Fig keeps a search index so it can find the right table without scanning everything. It lives in Google Cloud (Vertex AI Vector Search) in the United States. It holds more than any single question sends: table and field names, types, and descriptions, summaries of each field, a few example rows, how your automations, dashboards, and saved questions are set up, the questions people ask, and files you upload. Personal details are removed from example rows and field summaries, but not from descriptions or uploaded files. Google filters every search to your company. Entries are deleted when you delete the table, turn AI off, or your organization is deleted.
Quality review. We read real conversations to make Celeste more accurate. That isn't training an AI model. Conversations are screened for personal details automatically, and a person checks anything flagged before it's used. To opt your company out, email privacy@gofig.ai.
AI tools you connect. You can connect an outside AI assistant to Go Fig through our MCP server (the standard way AI assistants plug into other tools). Data you pull into that assistant goes to its provider under your own agreement with them. We verify the connection and log what it reads. See section 3.4 of the DPA.
Personal data
Personal data (often called PII) means details like email addresses and phone numbers. Go Fig removes them from what it sends to AI providers and from every answer before you see it.
There are two checkpoints. One runs before anything goes to an AI provider, and one runs before an answer reaches you.
| Type | How it's spotted |
|---|---|
| Social Security numbers | Matches the standard format |
| Credit card numbers | Matches the standard format, plus the Luhn check that confirms it's a real card number |
| Email addresses | Matches the standard format |
| Phone numbers | Matches US phone formats |
Audit trail
Every answer has a Show work button that shows exactly which data Celeste used and how she got the answer. Admins see every trail in their organization. Everyone else sees their own.
Go Fig keeps the full story behind each answer for 90 days. A record of who asked, when, and what it cost is kept longer.
Each record holds the question, the AI model used at each step, the tables and fields it looked at, the database code (SQL) it wrote, the answer, and how long and how confident each step was. No one can see another company's records. Once someone leaves your company, they can't open even their own past conversations.
Admins also get an AI activity page for the whole company. It shows who asked what and when, the data used, the models, and the credits spent. You can filter by person and date, look back up to 400 days, and page through the 500 most recent interactions, 25 at a time.
| Record | Kept |
|---|---|
| Your questions | Readable for 90 days after the conversation starts |
| Decision trails (the Show work detail) | Written detail and SQL withheld past 90 days, then deleted once the interaction is 90 days old |
| Who asked, when, which models, what it cost | Kept longer than 90 days |
| Usage records (model, tokens, cost, and credits, with no content) | Seven years, for tax and accounting. The name of who used it is removed after 90 days |
Tenant isolation
Tenant isolation means one customer can never reach another's data. It's enforced in two separate places, and every safeguard is always on. Any attempt to reach another company's data is blocked and logged.
Four protect your data when AI looks things up. Four protect it everywhere else.
The DPA's Annex II covers the safeguards everywhere else in Go Fig. This page adds the AI lookup ones on top. The one exception, on purpose, is Go Fig's own help documentation, which every customer shares and which never contains customer data.
Plans
Every plan gets all six.
Larger plans add finer access controls, like custom data roles, hiding or masking single fields, and a permission audit log. They also get the full SOC 2 report under NDA. On every plan we answer security questionnaires in writing. Email security@gofig.ai for a summary of how we protect data. We'll confirm what your plan includes on your demo.
Documents
Security overview, policies, and SOC 2 status
Every vendor that processes your data
The legal version of this page
Section 3.6 covers the security reports we share
What we collect and why
security@gofig.ai
Data from the apps and spreadsheets you connect is stored in Google Cloud in the United States, in storage only your company can reach. It stays in Google Cloud Storage's US multi-region, so it never leaves the country. If you connect your own database, your data stays there and Go Fig reads it in place. The keys to that storage are replaced every 90 days.
Only people you authorize. Go Fig staff may look at it when needed to fix a problem or answer a support request. Every access is logged and can be reviewed.
Never. We use customer data only to provide the Go Fig service. We may use anonymous, combined usage patterns to improve the product, but your data is never used to train AI models.
You have 30 days to export everything in standard formats. Then we delete it from our live systems and confirm in writing if you ask. Encrypted backups age out on a rolling schedule and are never put back into use. Everything is fully deleted within about 51 days.
Enterprise customers can request the report itself under NDA. On any plan we'll send a summary of how we protect data and answer your security questions in writing. Ask at security@gofig.ai.
We have a written plan for handling security incidents, and our SOC 2 Type II audit checked it. If a breach affects your data, we tell you promptly and within 72 hours of learning about it.
No, and it isn't meant to be. Go Fig isn't a system of record (the official home for regulated records). Keep Part 11 records in the validated systems built for them. If data you plan to connect falls under Part 11, HIPAA, PCI-DSS, or similar rules, section 3.3 of our DPA requires extra written terms first. Talk to us before you connect it.
A solutions engineer walks your reviewer through the controls on your real setup.