Skip to content

Workflow Inspector

Data handling for workspace buyers

A product and procurement overview, reviewed September 20, 2026. This page describes the service and its boundaries; it is not a security certification or an independent penetration-test report.

What to submit

Use anonymized workflow descriptions, role names, relevant process evidence and aggregate observations. Do not submit credentials, full payment-card details, classified information, regulated sensitive records, or information whose confidentiality terms prohibit processing by a third-party AI service.

Providers involved

Current service providers and purposes
ProviderPurpose
RenderApplication hosting and operational logs
NeonPostgreSQL storage for application records
OpenAIAI processing of submitted diagnostic intake
StripeHosted payments and subscription management
ResendTransactional and opted-in email delivery
Google/GmailDedicated support mailbox; Google sign-in when chosen
GitHubOptional account sign-in
Google measurement servicesOptional analytics and advertising measurement when allowed in Privacy choices

This overview does not promise a particular data residency arrangement or a negotiated processing agreement. If your procurement rules require one, ask before submitting data. The Privacy Policy describes data uses and choices.

Access and sharing

Accounts use verified sign-in and signed HttpOnly sessions. Workspace permissions are checked on the server. Owners and administrators can access department records; ordinary members and viewers are limited to workspace-wide and assigned-department records. Sharing selected report findings is explicit. Public report or score links, where created by the user, are bearer links: anyone with the link may access the shared view until it is revoked.

Retention and exports

Cancellation stops paid work at the period end and does not delete retained records. Authorized users can read retained workspace records and export individual workflows. Removing a member revokes workspace access; shared contributions remain. Workspace deletion removes content and membership, while minimal billing linkage remains for payment events and required records. Copies exported by recipients are outside the application's control. Contact support for account deletion or questions about retained records.

Security questions and incidents

Email support.handoffdiagnostic@gmail.com with a concise description, affected page and a safe reproduction. Do not send exploit payloads containing real customer data or credentials. Ask about any required DPA, residency terms, audit report, backup recovery objectives or incident commitments before relying on them; this site does not claim SOC 2 or ISO certification.

Read the role and workflow guide · Workspace purchase terms