DocsSecurity and plans
Guardian and security
How Adea keeps your data safe. A read-only connection, a check on every pull of data, and an administrator's approval where you want one.
On this page
A stolen password or a careless request can’t pull your customers’ data out of Adea in bulk. This page shows what stops it.
Adea only reads
Adea connects with a user that can only read, and checks that before it connects. It refuses a user that can write. Adea never writes to your database, your code or any other system you connect. See Connect a database.
It keeps no copy
For databases and code, Adea reads what a question needs, works out the answer and drops the rows. Each job runs in its own short-lived process, so one company’s data never shares memory with another’s.
Where your data is
Adea and its database run in the EU. Adea reaches your database from fixed addresses that it shows when you connect, so you can allow exactly those and nothing else. Your data is never used to train AI models.
What Guardian checks
Guardian looks at every pull of data, whoever asks: you, a colleague, a scheduled list or an AI assistant. It weighs:
- Personal data. Columns that hold names, emails, phone numbers, addresses, ID numbers and the like, and whether a result is mostly made of them. A count of members is not personal data. A list of their emails is.
- How much. The number of rows, and how that compares with what this person normally pulls.
- How unusual. A first export, the same pull repeated in a short while, or a pull at an hour the person never works.
- What the request says. Instructions hidden in data, and requests for passwords or keys.
What Guardian does
- On every plan, Guardian flags what looks unusual. You see flags in the decision log and in a digest, and ordinary work is never blocked.
- On the Business plan, Guardian can also hold a request until an administrator approves it. Every administrator who has been in the company for a day gets a link to approve or reject. An approval covers the same request, with up to 10 % more rows, for 24 hours. The person who asked is told when it’s decided.
- Weakening protection takes two people. Turning off a rule or lowering a limit needs a second administrator to approve, or it takes effect only after 24 hours unless someone stops it. This applies on every plan.
- If Guardian can’t run, requests for personal data, exports and changes to protection wait, instead of going through unchecked. Everyday questions about numbers carry on.
A request that Guardian holds never costs a credit.
The log
Guardian keeps a decision log, and a security log that can’t be altered without it showing. On the Business plan you can export the log.
On the Business plan
Business adds approvals, your own rules written in plain words (“hold any export over 500 rows”), the log export and the option to require sign-in with Google or Microsoft. See Credits and plans.
Questions from your security team
Write to security@adea.app.
Still stuck? Write to hello@adea.app. A person answers.