Security at Andrew
We know we're asking you to trust us with your most sensitive information: your books, your cap table, your bank data. Here's how we protect it, in plain terms.
Built for founders who take trust seriously.
Your data is isolated from every other customer.
Each organization's data is separated at the database level using row-level security, enforced on every request. One customer cannot access another customer's data.
Your data is encrypted.
All data is encrypted in transit using TLS, and encrypted at rest by our infrastructure providers. Credentials for connected accounts, such as banking and email tokens, carry a second layer of encryption applied by Andrew before they are stored. Database connections are encrypted and require verified certificates.
Sign-in is passwordless.
Andrew uses one-time magic links instead of passwords, so there are no stored passwords to leak or reuse. Access is limited to invited users during our private beta.
We run on trusted, independently audited infrastructure.
Andrew is built on Vercel, Neon, and Cloudflare, which maintain their own SOC 2 and industry certifications. Your data lives on infrastructure that is already independently audited.
We follow least-privilege access.
The application connects to your data using a restricted role that cannot bypass our security rules or alter the database structure.
Who can reach your data
Andrew is operated by a small team. Access to production systems is limited to people who need it to run and support the service, and today that is the founder. We access customer data only to investigate a problem you have reported, to fix a fault affecting your account, or where the law requires it. We do not browse customer books or documents.
You approve material actions.
Andrew proposes; you decide. Material financial actions are surfaced for your approval rather than executed automatically. Your books remain your record.
We're building toward independent validation.
We're an early-stage product in private beta, and we're candid about that. We don't yet hold formal third-party certifications. As we grow, our security roadmap includes:
- SOC 2 Type II: the standard independent audit for software handling financial data, and our highest-priority certification.
- Continuous controls monitoring through a compliance platform.
- A formal, documented incident-response and data-retention policy.
Reporting a vulnerability
If you believe you have found a security vulnerability in Andrew, please report it to security@agentandrew.ai. Include enough detail for us to reproduce the issue.
We will acknowledge your report within 2 business days and keep you updated as we investigate.
We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly, that you do not access, modify, or delete data belonging to anyone else, and that you do not degrade or disrupt the service for other users.
We will not pursue legal action against researchers who report in good faith and follow these guidelines.
Have security questions?
Have security questions or specific requirements? Contact us at security@agentandrew.ai.
Email us