Paius logo new - no backgroundPaius wordmark
HomeSign in

Legal

Security & Trust Center

Security & Trust Center

Effective Date: July 13, 2026
Last Updated: July 13, 2026

This Security & Trust Center describes current security, privacy, vendor, data handling, and operational practices for Paius, operated by Kinard Applied Solutions LLC through the product Paius (“Paius,” “we,” “us,” or “our”).

This page is informational and does not create additional contractual warranties unless expressly incorporated into a signed agreement.

1. Security Overview

Paius is designed to help users manage AI workflow costs, risk, approvals, analytics, receipts, and business usage records. Paius uses administrative, technical, and organizational safeguards designed to protect customer information.

No system is perfectly secure. Paius continuously evaluates its practices and may update this page as the Service matures.

2. Hosting and Infrastructure

Paius currently uses:

  • Vercel for hosting and deployment;
  • Neon for database infrastructure;
  • Stripe for payment processing;
  • PrivateEmail for email services;
  • Resend for transactional email delivery where configured;
  • Google OAuth for authentication support;
  • Optional SMTP email providers configured by Paius customers or operators;
  • Optional Sentry monitoring for error diagnostics where configured;
  • OpenAI, Anthropic, and Google Gemini as AI infrastructure providers where applicable.

3. Encryption

Paius uses HTTPS/TLS encryption in transit.

Paius relies on provider-supported encryption at rest for hosted infrastructure and database services where available.

4. Authentication

Paius supports or plans to support:

  • Email and password authentication;
  • Google OAuth;
  • Email verification;
  • Password reset workflows;
  • Session-based authentication;
  • Role-based access controls.

Passwords are hashed and are not stored in plain text.

5. Access Controls

Paius uses role-based access controls for organization administrators and team members. Organization administrators may be able to view and manage team usage, preflight assessments, receipts, approvals, risk indicators, costs, analytics, users, and workspace settings.

Administrative access to production systems should be limited to authorized personnel or contractors with a business need.

6. Customer Data Handling

Paius may store Customer Content, including workflow descriptions, prompts, uploaded files, cost estimates, receipts, approvals, analytics, and debugging records.

Paius uses or may use AI service providers, including OpenAI, Anthropic, and Google Gemini, to support product functionality and service operations.

Under Paius's current architecture and feature configuration, customer-submitted prompts, workflow descriptions, uploaded files, and Customer Content are not transmitted to external AI model providers unless Paius discloses that processing, obtains any required consent, or the customer enables a feature that requires such transmission.

Paius does not use Customer Content to train Paius models and does not fine-tune AI models using Customer Content.

We may use anonymized, aggregated, or de-identified data to understand product usage, improve system performance, develop features, and evaluate business trends, provided that such data does not identify a customer or individual.

7. Data Retention

We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain business records.

Current retention periods include:

  • Account information: for the life of the account and for a reasonable period after closure;
  • Workspace records and Customer Content, including inputs, outputs, receipts, analytics, and debugging records: up to five years unless deleted earlier in accordance with policy or applicable law;
  • In-app workflow prompt and output content: prompt and output content for in-app workflow execution follows the workspace retention setting: full, redacted, or none;
  • Billing, tax, and accounting records: up to seven years;
  • Support emails: as long as needed for support, compliance, and business records;
  • Deleted account data: generally deleted or de-identified within 30 days after a verified deletion request, subject to lawful retention exceptions.

Backups, if any are later implemented, may retain limited data for a short period before deletion through ordinary backup rotation.

8. Backups and Recovery

Paius does not currently represent that it maintains a customer-facing backup or disaster recovery program. Paius may rely on infrastructure-provider resilience and may implement formal backup procedures as the product matures.

Customers should maintain their own copies of critical records where appropriate.

9. Incident Response

Paius maintains an incident response process designed to identify, investigate, contain, and address security incidents.

If Paius confirms a security incident affecting customer data, Paius will notify affected customers without undue delay and provide information reasonably available at the time.

10. Payments

Paius uses Stripe for payment processing. Paius does not directly store full payment card numbers. Payment processing is handled by Stripe under Stripe’s own security and compliance program.

11. Analytics

Paius currently uses Vercel Analytics. Paius does not currently use advertising pixels, retargeting pixels, Meta Pixel, Google Ads tags, or LinkedIn Insight Tag.

12. Subprocessors

Paius maintains a Subprocessor List identifying key vendors that support the Service. Customers should review the Subprocessor List for current vendor information.

13. Compliance Status

Paius does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or similar certification unless expressly stated in writing.

Paius may pursue additional security reviews, audits, or certifications as the business grows.

14. Customer Responsibilities

Customers are responsible for:

  • Using strong passwords;
  • Protecting account credentials;
  • Managing user access and administrator permissions;
  • Removing users who no longer need access;
  • Reviewing outputs before relying on them;
  • Maintaining copies of critical records;
  • Avoiding unnecessary submission of sensitive or regulated data;
  • Using Paius in compliance with law and internal policies.

15. Security Contact

Security questions or concerns may be sent to:

support@getpaius.com

Paius wordmark

Built for the next generation of managers leading AI-powered work.

Product

  • Product
  • Integrations
  • Pricing
  • Start Assessment

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Agreement
  • Billing & Subscription Policy
  • Refund & Cancellation Policy
  • AI Disclaimer
  • Security & Trust Center
  • Subprocessor List
© 2026 Paius. All rights reserved.