Security & privacy policy

Built for sensitive
project data

Emerald handles confidential contracts, drawings, and financial data. Here is exactly how we protect it.

Last updated June 2026
None
Documents Stored
Never
Data Sold to Third Parties
Azure
Infrastructure
AES-256
Encryption

Data We Collect

  • Your name and email address, provided via Microsoft login.
  • Questions you ask Emerald during your session.
  • Usage logs for security auditing and compliance.
  • Feedback you provide (thumbs up/thumbs down).

What We Don't Collect

  • We do not sell, rent, or share your data with third parties.
  • We do not use your data to train AI models.
  • We do not track you across other websites or applications.

How Your Data Is Protected

  • All data encrypted in transit using HTTPS/TLS 1.2+.
  • All data encrypted at rest using AES-256 (Azure platform-managed keys). Authentication tokens are additionally encrypted at the application layer.
  • Project documents and content are read live to answer your questions and are not persisted; question text is retained for up to 24 hours for quality assurance, then automatically deleted.
  • Hosted on Microsoft Azure, an enterprise-grade, SOC2-compliant infrastructure.
  • Access controls ensure only authorized users on your approved list can log in.
  • Session timeout after 8 hours with a 10-minute warning.
  • Full audit log of all activity. Every login, question, and download is recorded.
  • Rate limiting to prevent abuse and unauthorized bulk access.

Your Project Documents

  • Documents are only used to answer your questions and nothing else.
  • Documents are never shared with other Emerald clients.
  • Document access is scoped to your account only.

Third-Party Services

  • Microsoft Azure for cloud hosting and authentication.
  • Anthropic Claude as the AI language model for generating responses. Data sent to Anthropic's API is not retained and is not used to train Anthropic's models.
  • All vendors are enterprise-grade with their own security certifications.

Compliance & Auditing

  • All user activity is logged with timestamp, user identity, and IP address.
  • Audit logs are retained to support security review and future SOC2 certification.
  • Emerald is actively working toward SOC2 Type I certification.
  • Security controls are reviewed and updated regularly.

Contact

Product
Agents Integrations System Status
Help Center
Contact Us FAQ Guides
Company
About Privacy Terms
© 2026 Emerald. All rights reserved.