security

How we handle the work you connect.

Repos, social accounts, documents, recordings: ReadyToEdit reads the real material. These are the guarantees around it.

The guarantees

  1. Your workspace is isolated twice

    Every query is scoped to your workspace in the application, and the database enforces the same boundary again with row-level security policies. Two independent layers have to fail before anyone else’s query touches your rows.

  2. Encrypted in transit and at rest

    All traffic runs over TLS. Data lives in managed Postgres with encryption at rest, and media in managed object storage with the same.

  3. Your content is not training data

    Drafts are generated with foundation models accessed through AWS Bedrock, which does not use your content to train models. Neither do we. What ReadyToEdit learns from your edits is stored inside your workspace and applied only to your drafts.

  4. Read-only connections

    Social and repository connections are read-only. ReadyToEdit ingests what you shipped and posted; it never posts, pushes, or publishes on your behalf. Nothing ships without your approval.

  5. Real authentication, scoped invitations

    Sign-in and sessions are handled by Clerk. You can invite someone to a whole workspace or to a single project — an editor invited to one project sees that project.

  6. Your data stays yours

    Everything ingested is browsable and deletable from inside the app. If you leave, ask and we delete the workspace and every copy of it.

Certification

ReadyToEdit is an early-stage product and has not completed a SOC 2 audit. What it has today is the architecture above: isolation in two layers, encryption by default, read-only connections and no training on your content. This page will list a certification once one is complete.

Security questions, or something you need before connecting a private repo? Ask. The person who wrote the isolation layer answers.

Connect your first repo.