Security
Built to ask first — in product and in posture.
Gradia handles customer records, quotes and approvals. The practices below are specific and verified. We do not claim certifications, recovery targets or blanket guarantees.
Your shop's data stays yours
Every shop is isolated at the database layer — row-level security on all tables, with machine paths scoped to a single shop.
You're always in control
Customer-facing actions start with approval required. Connecting a channel does not automatically allow every action on it.
Full audit trail
Agent runs, plans and actions are recorded so you can see what was proposed, held, executed or failed.
Consent and opt-out
STOP, do-not-contact and destination-bound permissions are treated as hard constraints. A pilot request is not blanket consent for marketing texts.
Credentials encrypted at rest
Per-shop credentials are stored with AES-256-GCM encryption. Provider webhooks are signature-verified and fail closed when secrets are unset.
We do not claim certifications we have not earned. Customer-data export is part of the intended product; self-serve deletion is not claimed as complete. Account removal today is a manual, founder-assisted process. Gradia is not a payment processor. Questions: trygradia@gmail.com.
Help shape Gradia in a real shop.
Tell us how your business handles inquiries today. Request access to the controlled pilot, and we'll follow up about fit and availability.
Requesting access does not create an account or start a subscription.