SOC 2 Type II certified Nothing sends without your approval Your data never trains AI
Log in Schedule a demo Schedule a demo

Your customers' data stays yours

See exactly what Go Fig can read, what it stores, and what it never touches. Every safeguard your security team will ask about is on this page.

Visit the trust center See the documents
SOC 2 Type II audited Checked by an independent auditor Encrypted when sent and stored TLS 1.2 or higher and AES-256 Walled off from other companies Eight safeguards, always on Never used to train AI Business AI plans that never learn from it

Every step your data takes is guarded

Here's what happens when you ask Go Fig a question.

Step 1

Your systems

The CRM, inbox, and data you connect. Go Fig only reads unless you turn writing on.

Step 2

Your own workspace

Every request is checked so it only touches your company's data.

Step 3

Personal data removed

Only what the question needs goes out. Emails, phone numbers, card numbers, and Social Security numbers are removed first.

Step 4

AI provider

We only use their business plans. Their terms say your data never trains their AI.

Step 5

Answer and audit trail

Personal details are removed again on the way back, and the whole exchange is logged.

The four things security teams ask about first

Go Fig only reads until you let it write

Celeste, Go Fig's AI analyst, can look at your data to answer a question. She can't change or delete anything.

Every write is logged. Every change Go Fig makes in your tools is recorded in a log your team can review.

How writing back works
Writing back for your organization QuickBooks Gmail Slack

Personal details are removed both ways

Email addresses, phone numbers, Social Security numbers, and credit card numbers are removed before anything reaches an AI provider. They're removed again before you see a response.

Renewal contact [email] [phone]
What gets scrubbed

Every answer shows its work

Every conversation with the AI is logged on every plan, so you can always see which data Celeste used.

1 Question

Which deals went quiet this month?

2 Data used

Tables: deals, contacts

3 Answer written Read-only
What is kept and for how long

Eight safeguards wall off your data from other companies

Four protect your data when AI looks things up. Four protect it everywhere else.

Every search entry tagged with your company
Google filters every search to your company
Access checked before every action
Every piece of data tagged with your company
Every request checked against your company
Every database lookup filtered to your company
Separate storage for each company
People see only what their role allows
How isolation is enforced

The details behind each safeguard

Open any section for the full detail your security team will want.

It only makes changes where you allow it

Writing back means Go Fig making a change in one of your tools, like updating a CRM record or sending an email. An admin turns it on for your company, then for each tool. A personal inbox or CRM login also needs its owner's OK. No plan turns it on for you. Every change Go Fig makes in your tools is recorded in a log your team can review.

What writing back can do once it's on

Once an admin turns it on, these are the kinds of changes Go Fig can make in the tools you connect.

CapabilityExample
AccountingCreate invoices, bills, journal entries, estimates, customers, and vendors in QuickBooks
EmailSend through a connected Gmail or Outlook mailbox
MessagingPost to Slack
ProductivityWrite to Notion, create calendar events, update CRM records

Your plan decides which tools you can connect, so it also limits where Go Fig could make changes. Think twice before turning this on for a tool that emails customers or holds your official records.

What the AI sees and what it never sees

In short, the AI sees your question, the names of your fields, and at most 100 example records you're allowed to see. It never sees passwords, other companies' data, or fields you can't see. The full detail for your security team is below.

Which providers we use and their training terms

The AI companies we use have agreed not to learn from your data. We only use their paid business plans (business API tiers), and their standard terms say data sent this way isn't used for training. We never use their consumer apps, and we never train (fine-tune) a model on customer data. A backup provider answers when the main one can't.

ProviderRoleTraining
Google, Gemini via Vertex AIMain provider, every planNot used for training, under Google Cloud's data terms
OpenAI, GPTBackup and some specific tasks, every planDoesn't train on data sent through its API
Anthropic, ClaudeBackup on some plans. Starter sends no data to AnthropicDoesn't train on data sent through its API
Exactly what's sent and what never is

To answer a question, the AI needs to know what you asked and what your data looks like. It gets small, capped samples, never your whole database. Go Fig uses your field names and types to write a query (the request that pulls the right data).

SentWhy
Your question and the conversation so farTo understand what you're asking
Table names, field names, and field typesTo write an accurate query
How your team defines its metricsTo use your company's own terms
A few example values, with personal details removedTo see what the data looks like
Up to 100 example rows from a relevant tableTo base the answer on your real data
Query results, cut to a set sizeTo explain the result in words

Example rows and results are filtered by your role first. A field that's hidden or masked for you is left out of what gets sent. Your logins to your tools are never sent either.

Never sentHow
Whole tables or bulk exportsOnly small, capped samples are sent
Passwords, API keys, OAuth tokensNever included in anything sent
Other companies' dataWalled off by tenant isolation
Fields your role can't seeRemoved before anything is sent
Search, quality review, and AI tools you connect

Three more places your data is used, each with its own limits.

Search index. Go Fig keeps a search index so it can find the right table without scanning everything. It lives in Google Cloud (Vertex AI Vector Search) in the United States. It holds more than any single question sends: table and field names, types, and descriptions, summaries of each field, a few example rows, how your automations, dashboards, and saved questions are set up, the questions people ask, and files you upload. Personal details are removed from example rows and field summaries, but not from descriptions or uploaded files. Google filters every search to your company. Entries are deleted when you delete the table, turn AI off, or your organization is deleted.

Quality review. We read real conversations to make Celeste more accurate. That isn't training an AI model. Conversations are screened for personal details automatically, and a person checks anything flagged before it's used. To opt your company out, email privacy@gofig.ai.

AI tools you connect. You can connect an outside AI assistant to Go Fig through our MCP server (the standard way AI assistants plug into other tools). Data you pull into that assistant goes to its provider under your own agreement with them. We verify the connection and log what it reads. See section 3.4 of the DPA.

Personal details are removed on the way out and on the way back

Personal data (often called PII) means details like email addresses and phone numbers. Go Fig removes them from what it sends to AI providers and from every answer before you see it.

What gets removed and how it's spotted

There are two checkpoints. One runs before anything goes to an AI provider, and one runs before an answer reaches you.

Before sending to AI

  • Example values from your tables
  • Table descriptions your team writes, before they go into the search index
  • Example values from your business definitions (the semantic model)
  • One last check on the full message before it's sent

Before showing a response

  • Personal details removed
  • Links that can't be verified removed
  • Made-up numbers flagged
  • Database code (SQL) that could change data removed from what's shown
TypeHow it's spotted
Social Security numbersMatches the standard format
Credit card numbersMatches the standard format, plus the Luhn check that confirms it's a real card number
Email addressesMatches the standard format
Phone numbersMatches US phone formats

Every AI interaction is logged on every plan

Every answer has a Show work button that shows exactly which data Celeste used and how she got the answer. Admins see every trail in their organization. Everyone else sees their own.

What's kept and for how long

Go Fig keeps the full story behind each answer for 90 days. A record of who asked, when, and what it cost is kept longer.

Each record holds the question, the AI model used at each step, the tables and fields it looked at, the database code (SQL) it wrote, the answer, and how long and how confident each step was. No one can see another company's records. Once someone leaves your company, they can't open even their own past conversations.

Admins also get an AI activity page for the whole company. It shows who asked what and when, the data used, the models, and the credits spent. You can filter by person and date, look back up to 400 days, and page through the 500 most recent interactions, 25 at a time.

RecordKept
Your questionsReadable for 90 days after the conversation starts
Decision trails (the Show work detail)Written detail and SQL withheld past 90 days, then deleted once the interaction is 90 days old
Who asked, when, which models, what it costKept longer than 90 days
Usage records (model, tokens, cost, and credits, with no content)Seven years, for tax and accounting. The name of who used it is removed after 90 days

Your data stays separate from every other customer's

Tenant isolation means one customer can never reach another's data. It's enforced in two separate places, and every safeguard is always on. Any attempt to reach another company's data is blocked and logged.

The eight safeguards

Four protect your data when AI looks things up. Four protect it everywhere else.

When AI looks up data

  1. Every entry in the search index is tagged with your company's ID
  2. Google filters each search to your company, not just our own code
  3. Every action checks your company's access before it runs
  4. Your company's ID is stored on every piece of data, so searches can filter on it

Everywhere else in Go Fig

  1. Every request is checked against your company
  2. Every database lookup is filtered to your company
  3. Separate storage for each company, with its own access keys
  4. Role-based access inside your company, so people see only what their role allows

The DPA's Annex II covers the safeguards everywhere else in Go Fig. This page adds the AI lookup ones on top. The one exception, on purpose, is Go Fig's own help documentation, which every customer shares and which never contains customer data.

Security isn't an upsell

Every plan gets all six.

AI providers that don't train on your data
Personal details removed on the way out and on the way back
Your data walled off from every other company's, with eight safeguards
Read-only by default
A full audit log of every AI interaction
One switch that turns AI off for your whole company, so no data reaches any AI provider

Larger plans add finer access controls, like custom data roles, hiding or masking single fields, and a permission audit log. They also get the full SOC 2 report under NDA. On every plan we answer security questionnaires in writing. Email security@gofig.ai for a summary of how we protect data. We'll confirm what your plan includes on your demo.

Everything your security team will ask for

Trust center

Security overview, policies, and SOC 2 status

Security questions

Where is my data stored?

Data from the apps and spreadsheets you connect is stored in Google Cloud in the United States, in storage only your company can reach. It stays in Google Cloud Storage's US multi-region, so it never leaves the country. If you connect your own database, your data stays there and Go Fig reads it in place. The keys to that storage are replaced every 90 days.

Who can access my data?

Only people you authorize. Go Fig staff may look at it when needed to fix a problem or answer a support request. Every access is logged and can be reviewed.

Do you sell or share customer data?

Never. We use customer data only to provide the Go Fig service. We may use anonymous, combined usage patterns to improve the product, but your data is never used to train AI models.

What happens to my data if I cancel?

You have 30 days to export everything in standard formats. Then we delete it from our live systems and confirm in writing if you ask. Encrypted backups age out on a rolling schedule and are never put back into use. Everything is fully deleted within about 51 days.

Can I get the SOC 2 report?

Enterprise customers can request the report itself under NDA. On any plan we'll send a summary of how we protect data and answer your security questions in writing. Ask at security@gofig.ai.

How do you handle a breach?

We have a written plan for handling security incidents, and our SOC 2 Type II audit checked it. If a breach affects your data, we tell you promptly and within 72 hours of learning about it.

Is Go Fig validated for FDA 21 CFR Part 11?

No, and it isn't meant to be. Go Fig isn't a system of record (the official home for regulated records). Keep Part 11 records in the validated systems built for them. If data you plan to connect falls under Part 11, HIPAA, PCI-DSS, or similar rules, section 3.3 of our DPA requires extra written terms first. Talk to us before you connect it.

Bring your security review to the demo

A solutions engineer walks your reviewer through the controls on your real setup.

Schedule a demo