Skip to content

Trust center

The safest AI action is the one
a person approved.

Security at BudAlly starts with the product design: agents hold no execute rights, every write runs under a named person's credential, and every proposal leaves an audit trail you can export. Then the usual controls on top.

  • SOC 2 Type IIPlaceholder: [STATUS · DATE]
  • Metrc Validated IntegratorPlaceholder: [STATUS · STATES]
  • Pen testPlaceholder: [LAST DATE · FIRM]
  • IncidentsChangelog & incident history

01 · Draft-then-approve as a control

Agents can't do anything. They can only propose.

Every agent run produces proposals with evidence, a confidence score, the rules it checked and a precondition hash. If the world changes before approval — a price moved, a manifest was edited — the proposal is superseded and can't be approved. Cutovers and Metrc-affecting changes need two different approvers. There is no “approve all” anywhere in the product.

  • Executes under the approver's own POS or Metrc credential
  • Role-based access; maker ≠ checker on campaigns and cutovers
  • Learned rules are versioned and approved before they apply
  • Audit log: who, what, when, evidence, credential — exportable as CSV/JSON
PROPOSAL LIFECYCLE
  1. Proposed
  2. Reviewed
  3. Approved
  4. Revalidating
  5. Executing
  6. Executed
  7. Verified
  8. Superseded

The controls around it

  • 02 · Data ownership

    Yours. Contractually.

    Ledger, members, consent proofs, documents export in open formats at any time, on any plan. No resale, no cross-tenant training. Deleting a tenant purges within Placeholder: [N] days with a certificate.

  • 03 · Tenancy & aggregation

    k ≥ 8, or it doesn’t show.

    Each license is its own tenant row with its own credentials. Network medians need at least 8 contributors and explicit opt-in; Dutchie-connector rows are excluded from all benchmarks under its developer terms.

  • 04 · Model providers

    30-day retention or less. No training.

    Invoice PDFs and copy drafts go to a model provider under a zero-training, ≤30-day retention agreement. A zero-retention tier is available on Chain Ops. Providers are listed as sub-processors.

  • 05 · Infrastructure

    Encrypted, backed up, US-hosted.

    TLS 1.2+ in transit, AES-256 at rest, POS and Metrc keys in a vault with per-tenant rows, daily encrypted backups with Placeholder: [N]-day retention, US region: Placeholder: [PROVIDER · REGION]. Sentry for errors, no PII in traces.

  • 06 · Consent & marketing law

    Proof, not checkboxes.

    Every contact carries channel, timestamp, source and text version. No SMS without your own 10DLC and proven consent. CA financial-incentive notices and NY inducement bans are enforced before a draft exists (TCPA, CAN-SPAM, CCPA — counsel reviewed).

  • 07 · Access

    SSO, roles, sessions.

    Google and Microsoft SSO, SAML on Chain Ops, MFA enforced for approvers, role-based access down to store and module, session logs, kill switch per connector and per user.

Sub-processors

Sub-processors, what each one is used for and the region it runs in
ProviderPurposeRegion
Placeholder: [HOSTING PROVIDER]Application hosting, database, backupsUS
AnthropicModel provider for invoice capture and copy drafts (≤30-day retention, no training)US
ResendTransactional email (briefings carry titles and counts only)US
SentryError monitoring, PII scrubbedUS
Google Maps PlatformDelivery routing (addresses only)US
HeadsetLicensed market data (inbound only; no tenant data sent)US

Responsible disclosure

Found something? security@budally.com · PGP key on this page · we acknowledge within 2 business days and don't pursue good-faith researchers.

PGP fingerprint: Placeholder: [KEY]

Documents on request

SOC 2 report, pen-test summary, DPA, security questionnaire (CAIQ), business continuity plan.

Request the security packet

Questions your compliance officer will ask? Send them to us first.

Talk to security