Skip to main content

Security

Built to ask first — in product and in posture.

Gradia handles customer records, quotes and approvals. The practices below are specific and verified. We do not claim certifications, recovery targets or blanket guarantees.

Your shop's data stays yours

Every shop is isolated at the database layer — row-level security on all tables, with machine paths scoped to a single shop.

You're always in control

Customer-facing actions start with approval required. Connecting a channel does not automatically allow every action on it.

Full audit trail

Agent runs, plans and actions are recorded so you can see what was proposed, held, executed or failed.

Consent and opt-out

STOP, do-not-contact and destination-bound permissions are treated as hard constraints. A pilot request is not blanket consent for marketing texts.

Credentials encrypted at rest

Per-shop credentials are stored with AES-256-GCM encryption. Provider webhooks are signature-verified and fail closed when secrets are unset.

We do not claim certifications we have not earned. Customer-data export is part of the intended product; self-serve deletion is not claimed as complete. Account removal today is a manual, founder-assisted process. Gradia is not a payment processor. Questions: trygradia@gmail.com.

Help shape Gradia in a real shop.

Tell us how your business handles inquiries today. Request access to the controlled pilot, and we'll follow up about fit and availability.

Requesting access does not create an account or start a subscription.