Security

How SeamTrail keeps your data apart, encrypts tool logins, and shows people only what they are allowed to see.

This page explains how SeamTrail protects your data, in plain words.

Your data stays in your tools

Your documents, tickets and messages stay where they are. SeamTrail keeps what it needs to work:

  • short memory lines, each with a link back to its source,
  • the links between your work (which ticket came from which doc section, which pull request does which ticket),
  • the text of the doc sections you linked, so it can see exactly what changed.

Each org's data is kept apart

  • Every org's data is kept apart in the database itself, not only in the app. A request that does not name an org gets nothing back.
  • One org can never read another org's data. Automated tests check this.
  • Each org has its own audit log.

Tool logins are encrypted

When you connect a tool, SeamTrail receives a login token for it. These tokens are:

  • stored encrypted, with a separate key for each org, held in a managed key service.
  • never written to logs, error messages or API answers.

Personal logins work the same way. You can remove yours at any time in your own Settings → Connections.

Tokens for AI assistants and CI deploy keys are stored only as a hash. SeamTrail shows them once, when they are created.

People see only what they are allowed to see

  • Your own login for what you do. When you link an item, read a ticket live, or ask the agent, SeamTrail uses your own login to that tool. The tool decides what you can see. SeamTrail never falls back to an admin's access.
  • The org's connection for background work. Reading changes and keeping the memory up to date run on the connection an Admin or Manager made.
  • You link only what you can open. For Jira, Confluence and Slack, SeamTrail checks this with your own login before you link an item. Items from other tools can be linked only by an org Admin or Manager.
  • The feature is the boundary. Everyone on a feature sees all of its memory. Only the feature's people can open it.
  • Rank does not open content. Admins and Managers see names, people and usage. They do not read a feature's memory unless they are on it.

See Roles and permissions.

AI assistants act as you

  • An assistant sees only the features you are on, with your role.
  • You can see and revoke your assistants at any time. A revoked assistant is refused on its next call.
  • When you leave an org, your assistants stop working there.

Writing into your tools

SeamTrail reads first. It writes into a tool only for something a person did or turned on. For example:

  • a Jira change you confirmed in the chat, like moving a ticket,
  • an item you asked SeamTrail to create, like a Confluence page or tickets from the Plan,
  • adding a feature's people to its Slack channel and Miro boards,
  • the daily digest or the PR check, when someone turned them on,
  • a Slack direct message telling someone that their decision was replaced or contradicted.

It never edits your docs, and never comments on your tickets by itself.

The audit log

The audit log records who did what, and when: sign-ins, invites, role changes, connected tools and more. Records can only be added. Nobody can change or delete them.

HTTPS everywhere

All traffic to and from SeamTrail is encrypted with HTTPS (TLS). Plain HTTP is redirected to HTTPS.

Changes from your tools come in through SeamTrail's own door. Where a tool signs its messages, SeamTrail checks the signature.

AI and your data

SeamTrail uses an AI model to read changes and answer questions. It sends only what a task needs, for example the changed section and the titles of the tickets built on it.

Your content is not used to train AI models.

Disconnect at any time

Remove SeamTrail's app inside the tool: uninstall the Slack app or the GitHub App, or revoke the Atlassian app. The connection breaks at once, and SeamTrail stops reading from that tool.

More

See Privacy for the privacy policy and terms.

On this page