Trust & data handling

Security at Surfaice

Surfaice is an agentic AI layer for retail real estate, construction, and facilities. It reads the systems you already run, reasons over them, and gives the work back to your team.

This page describes what that means for your data — what Surfaice can see, what it stores, who approves it, and where we are on compliance. We've kept it to what we can support. Anything marked in progress is in progress.

SOC 2 Type I — in progress

US-hosted (Google Cloud)

No customer data trains any model

Request the security package

What Surfaice actually is

Surfaice is an agentic system of actions that connects to the systems of record you already run — Lucernex, CoStar, SharePoint, your DMS, or anything else in your stack. It reads them, acts on what it finds, and returns the work to your team. It does not copy or clone them, and it does not become a second system of record.

The closest familiar analogy is a business-intelligence layer. A BI tool connects to your systems, reads what the signed-in user is already allowed to read, and produces a report. Surfaice works the same way, with one difference: it reads documents and email threads rather than tables, and it produces drafts and abstractions rather than charts.

A lease abstraction is a good example. The agent opens the original lease, the seven amendments, the estoppel, and the landlord letter — wherever they live — reads them in one pass, resolves which terms are current, and hands you the abstraction. The documents are read at run time. They are not copied into Surfaice to make that happen.

Your systems of record

Lucernex

CoStar

SharePoint

Outlook

Google Drive

Procore

Smartsheet

ServiceChannel

FEXA

Your data lives here. It stays here.

Surfaice · your isolated tenant

Permission gate

User-granted OAuth · exclusion lists

Context assembly

Read at run time, held only for the run

Agent reasoning

Your skills, your instructions

Audit log

Every request recorded

Persists here

Accounts

Encrypted connection tokens

Workspace config and skills

Audit logs

Items a user explicitly saves

Output

Lease abstraction

CAM audit

Draft reply

Critical-date alert

Writeback to your lease admin system

Delivered to your team, or written back to your system of record. Writes are scoped and explicit.

What we store, and what we don’t

Persists in SurfaiceNever copied into Surfaice
Account and user identityBulk copies of your mailboxes
Connection tokens, encryptedA mirror or sync of your SharePoint or DMS
Workspace configuration, skills, and instructionsA general-purpose lake of your documents
Audit and agent-run logsAny customer data used to train any model, ours or a vendor’s
Content a user deliberately saves — for example, a lease abstraction moved into workspace memoryAnything outside the scope you approved

Everything else is assembled for a single agent run and is not retained after it.

Permissions: you decide what Surfaice can see

Nothing connects without your IT team’s consent.

The Surfaice application is approved by your administrators in whichever workspace you run — Microsoft 365, Google Workspace, or another — on your timeline. Every system of record we connect to follows the same rule.

Email is connected by the individual user, to their own mailbox.

There is no tenant-wide mailbox read and no server-level access to your mail system. A user can only ever reach email they could already open themselves. No one’s mailbox is connected because someone else approved it.

You control who is even offered the connector.

Connector availability is governed by role inside Surfaice. Property management and lease administration can connect; everyone else never sees the option, regardless of tenant-level consent.

Exclusion lists are enforced across every skill.

Keywords, senders, domains, and folders can be excluded instance-wide — HR, legal, benefits, executive correspondence — and the exclusions apply to every email-touching skill by default, not one skill at a time. Your team can hold the pen on that list.

Permissions are inherited, never expanded.

A signed-in user sees exactly the data their existing role in Lucernex, CoStar, or SharePoint already grants them. Surfaice never grants someone access they didn’t already have.

Rollout is staged and reversible.

Connectors go live one at a time, each on your explicit sign-off, and access can be revoked in your identity provider at any time.

Reading data you didn't approve isn't just a policy problem for us — it's expensive. We have a direct interest in touching the smallest amount of your data that does the job.

AI model handling

Surfaice is model-agnostic — work is routed to whichever model fits the task. We hold a commercial agreement with every provider we use, and every one of those agreements carries zero-retention and no-training terms. Anything an agent sends for inference is not retained by the provider and is never used to train a model. All inference is US-region.

Three providers carry that work today.

ProviderRoleTerms
Microsoft Azure OpenAIPrimary inference, and voice transcriptionCommercial agreement · zero retention · no training
Google GeminiSecondary inference — Gemini Flash for fast tasks and repliesCommercial agreement · zero retention · no training
AnthropicComplex reasoning, skill development, and platform engineeringCommercial agreement · zero retention · no training

A person stays in the loop. Agents draft; your team reviews and sends. Any workflow that acts without review is one you explicitly configure and approve.

Tenant isolation and infrastructure

  • Every customer gets a dedicated, isolated environment with its own database. There is no shared multi-tenant store of customer content.
  • Hosted on Google Cloud Platform, US regions (us-central1, us-east1). Data does not leave the US.
  • Encrypted at rest (AES-256) and in transit (TLS 1.2+).
  • Cloudflare provides DNS, WAF, and edge protection, with US-pinned cache.
  • Sentry and Better Uptime provide error monitoring and continuous synthetic availability checks.

Access control and audit

  • Single sign-on Microsoft Entra ID, Google Workspace, and other SAML/OIDC providers.
  • Multi-factor authentication Supported and enforceable at the tenant level.
  • Role-based access Governs both data scope and which connectors a role may use.
  • Full audit trail Every agent request is logged — who asked, what was read, what was produced. Available to your team and exportable on request.

Subprocessors

SubprocessorRoleRegion
Google Cloud PlatformPrimary hosting and infrastructureUS (us-central1, us-east1)
Clerk Inc.Authentication and SSOUS
Microsoft (Azure OpenAI)Primary AI inference and voice transcriptionUS
Google (Gemini)Secondary AI inference for fast tasksUS
Anthropic PBCAI inference for complex reasoning and skill developmentUS
Google Cloud VisionOCR for photo captureUS
Cloudflare Inc.DNS, WAF, edgeGlobal, US-pinned cache
Sentry, Better UptimeError monitoring and synthetic checksUS

We keep this list current.

Compliance status, stated plainly

Surfaice is a young company. We're building the compliance program deliberately rather than claiming coverage we don't have.

SOC 2 Type IType I program in progress ahead of the independent audit — via Vanta, expected Q3/Q4 2026
Data residencyUS only
Model training on customer dataNone, contractually
  • Public product documentation Onboarding guides, use cases, skills library, data-handling concepts, and security overview — available without an NDA at docs.surfaice.pro.
  • Available under NDA Security Guide · Application Architecture Diagram · AI Governance Policy

Common questions

  • Why does Surfaice need access to the inbox at all? Lease and construction work lives in email — whichever client you use. Amendments, CAM reconciliation letters, default notices, and lien waivers arrive as attachments and are often filed nowhere else. An abstraction built without them is wrong.
  • Can Surfaice read our CEO’s email? No. Mailbox access is granted per user, by that user, and only for roles you’ve enabled. There is no tenant-wide mailbox access.
  • Can we limit it to property management only? Yes — both by role inside Surfaice and by scoping the SharePoint sites and mailboxes you approve.
  • Can we block topics like HR or legal? Yes. Instance-wide exclusion lists by keyword, sender, and domain, enforced across every email-touching skill.
  • Do you train on our data? No. Not our models, and not our vendors’.
  • Can we get audit logs? Yes. Every agent request is logged and available to your team.
  • What happens if we revoke access? Access stops immediately. Your data was never duplicated, so there is nothing to unwind in your systems of record. Deletion of the limited data that does persist in Surfaice is handled under your agreement.
  • How is this different from a BI tool? Structurally, it isn’t. It connects with the user’s own permissions and reports on systems of record. It reads documents instead of tables, and it drafts work instead of charts.

Contact

For security reviews and documentation requests: security@surfaice.pro. For privacy requests: privacy@surfaice.pro.

Product documentation: docs.surfaice.pro.

Reporting a vulnerability? See our Vulnerability Disclosure Policy.