Trust & data handling
Security at Surfaice
Surfaice is an agentic AI layer for retail real estate, construction, and facilities. It reads the systems you already run, reasons over them, and gives the work back to your team.
This page describes what that means for your data — what Surfaice can see, what it stores, who approves it, and where we are on compliance. We've kept it to what we can support. Anything marked in progress is in progress.
SOC 2 Type I — in progress
US-hosted (Google Cloud)
No customer data trains any model
Request the security package
What Surfaice actually is
Surfaice is an agentic system of actions that connects to the systems of record you already run — Lucernex, CoStar, SharePoint, your DMS, or anything else in your stack. It reads them, acts on what it finds, and returns the work to your team. It does not copy or clone them, and it does not become a second system of record.
The closest familiar analogy is a business-intelligence layer. A BI tool connects to your systems, reads what the signed-in user is already allowed to read, and produces a report. Surfaice works the same way, with one difference: it reads documents and email threads rather than tables, and it produces drafts and abstractions rather than charts.
A lease abstraction is a good example. The agent opens the original lease, the seven amendments, the estoppel, and the landlord letter — wherever they live — reads them in one pass, resolves which terms are current, and hands you the abstraction. The documents are read at run time. They are not copied into Surfaice to make that happen.
Your systems of record
Lucernex
CoStar
SharePoint
Outlook
Google Drive
Procore
Smartsheet
ServiceChannel
FEXA
Your data lives here. It stays here.
Surfaice · your isolated tenant
Permission gate
User-granted OAuth · exclusion lists
Context assembly
Read at run time, held only for the run
Agent reasoning
Your skills, your instructions
Audit log
Every request recorded
Persists here
Accounts
Encrypted connection tokens
Workspace config and skills
Audit logs
Items a user explicitly saves
Output
Lease abstraction
CAM audit
Draft reply
Critical-date alert
Writeback to your lease admin system
Delivered to your team, or written back to your system of record. Writes are scoped and explicit.
What we store, and what we don’t
| Persists in Surfaice | Never copied into Surfaice |
|---|---|
| Account and user identity | Bulk copies of your mailboxes |
| Connection tokens, encrypted | A mirror or sync of your SharePoint or DMS |
| Workspace configuration, skills, and instructions | A general-purpose lake of your documents |
| Audit and agent-run logs | Any customer data used to train any model, ours or a vendor’s |
| Content a user deliberately saves — for example, a lease abstraction moved into workspace memory | Anything outside the scope you approved |
Everything else is assembled for a single agent run and is not retained after it.
Permissions: you decide what Surfaice can see
Nothing connects without your IT team’s consent.
The Surfaice application is approved by your administrators in whichever workspace you run — Microsoft 365, Google Workspace, or another — on your timeline. Every system of record we connect to follows the same rule.
Email is connected by the individual user, to their own mailbox.
There is no tenant-wide mailbox read and no server-level access to your mail system. A user can only ever reach email they could already open themselves. No one’s mailbox is connected because someone else approved it.
You control who is even offered the connector.
Connector availability is governed by role inside Surfaice. Property management and lease administration can connect; everyone else never sees the option, regardless of tenant-level consent.
Exclusion lists are enforced across every skill.
Keywords, senders, domains, and folders can be excluded instance-wide — HR, legal, benefits, executive correspondence — and the exclusions apply to every email-touching skill by default, not one skill at a time. Your team can hold the pen on that list.
Permissions are inherited, never expanded.
A signed-in user sees exactly the data their existing role in Lucernex, CoStar, or SharePoint already grants them. Surfaice never grants someone access they didn’t already have.
Rollout is staged and reversible.
Connectors go live one at a time, each on your explicit sign-off, and access can be revoked in your identity provider at any time.
Reading data you didn't approve isn't just a policy problem for us — it's expensive. We have a direct interest in touching the smallest amount of your data that does the job.
AI model handling
Surfaice is model-agnostic — work is routed to whichever model fits the task. We hold a commercial agreement with every provider we use, and every one of those agreements carries zero-retention and no-training terms. Anything an agent sends for inference is not retained by the provider and is never used to train a model. All inference is US-region.
Three providers carry that work today.
| Provider | Role | Terms |
|---|---|---|
| Microsoft Azure OpenAI | Primary inference, and voice transcription | Commercial agreement · zero retention · no training |
| Google Gemini | Secondary inference — Gemini Flash for fast tasks and replies | Commercial agreement · zero retention · no training |
| Anthropic | Complex reasoning, skill development, and platform engineering | Commercial agreement · zero retention · no training |
A person stays in the loop. Agents draft; your team reviews and sends. Any workflow that acts without review is one you explicitly configure and approve.
Tenant isolation and infrastructure
- Every customer gets a dedicated, isolated environment with its own database. There is no shared multi-tenant store of customer content.
- Hosted on Google Cloud Platform, US regions (us-central1, us-east1). Data does not leave the US.
- Encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Cloudflare provides DNS, WAF, and edge protection, with US-pinned cache.
- Sentry and Better Uptime provide error monitoring and continuous synthetic availability checks.
Access control and audit
- Single sign-on Microsoft Entra ID, Google Workspace, and other SAML/OIDC providers.
- Multi-factor authentication Supported and enforceable at the tenant level.
- Role-based access Governs both data scope and which connectors a role may use.
- Full audit trail Every agent request is logged — who asked, what was read, what was produced. Available to your team and exportable on request.
Subprocessors
| Subprocessor | Role | Region |
|---|---|---|
| Google Cloud Platform | Primary hosting and infrastructure | US (us-central1, us-east1) |
| Clerk Inc. | Authentication and SSO | US |
| Microsoft (Azure OpenAI) | Primary AI inference and voice transcription | US |
| Google (Gemini) | Secondary AI inference for fast tasks | US |
| Anthropic PBC | AI inference for complex reasoning and skill development | US |
| Google Cloud Vision | OCR for photo capture | US |
| Cloudflare Inc. | DNS, WAF, edge | Global, US-pinned cache |
| Sentry, Better Uptime | Error monitoring and synthetic checks | US |
We keep this list current.
Compliance status, stated plainly
Surfaice is a young company. We're building the compliance program deliberately rather than claiming coverage we don't have.
| SOC 2 Type I | Type I program in progress ahead of the independent audit — via Vanta, expected Q3/Q4 2026 |
|---|---|
| Data residency | US only |
| Model training on customer data | None, contractually |
- Public product documentation Onboarding guides, use cases, skills library, data-handling concepts, and security overview — available without an NDA at docs.surfaice.pro.
- Available under NDA Security Guide · Application Architecture Diagram · AI Governance Policy
Common questions
- Why does Surfaice need access to the inbox at all? Lease and construction work lives in email — whichever client you use. Amendments, CAM reconciliation letters, default notices, and lien waivers arrive as attachments and are often filed nowhere else. An abstraction built without them is wrong.
- Can Surfaice read our CEO’s email? No. Mailbox access is granted per user, by that user, and only for roles you’ve enabled. There is no tenant-wide mailbox access.
- Can we limit it to property management only? Yes — both by role inside Surfaice and by scoping the SharePoint sites and mailboxes you approve.
- Can we block topics like HR or legal? Yes. Instance-wide exclusion lists by keyword, sender, and domain, enforced across every email-touching skill.
- Do you train on our data? No. Not our models, and not our vendors’.
- Can we get audit logs? Yes. Every agent request is logged and available to your team.
- What happens if we revoke access? Access stops immediately. Your data was never duplicated, so there is nothing to unwind in your systems of record. Deletion of the limited data that does persist in Surfaice is handled under your agreement.
- How is this different from a BI tool? Structurally, it isn’t. It connects with the user’s own permissions and reports on systems of record. It reads documents instead of tables, and it drafts work instead of charts.
Contact
For security reviews and documentation requests: security@surfaice.pro. For privacy requests: privacy@surfaice.pro.
Product documentation: docs.surfaice.pro.
Reporting a vulnerability? See our Vulnerability Disclosure Policy.
