▸ Trust · Security · Privacy

    Built so you can trust the answer.

    Predara reads your CRM the way a seasoned sales leader does — and that only works if every leader, ops team and security reviewer trusts how we handle the data underneath. Here's exactly how we do it.

    TRU-01

    GDPR compliant

    We process personal data lawfully, transparently and only for the purposes you'd expect from a sales intelligence platform.

    • Data Processing Agreement (DPA) available on request for every paying customer.
    • Subject Access, rectification, erasure and portability requests honoured within 30 days.
    • EU/UK data residency available; international transfers covered by Standard Contractual Clauses.
    • Sub-processors disclosed and kept to the minimum needed to run the service.

    TRU-02

    OAuth 2.0 authentication

    Predara never sees, stores or asks for your CRM password. Every connection is brokered through OAuth 2.0 with the narrowest possible scopes.

    • Industry-standard OAuth 2.0 authorisation code flow with PKCE.
    • Tokens encrypted at rest using AES-256, rotated automatically and revocable from your CRM at any time.
    • Read-only scopes by default — we only request additional scopes when a customer explicitly enables a feature that needs them.
    • Disconnecting in your CRM revokes Predara's access immediately, no email or support ticket required.

    TRU-03

    Read-only AI

    Predara is built to read your CRM, not to write to it. Our AI never edits records, creates tasks or messages your customers.

    • All analysis runs on a read-only mirror of your CRM data — your source of truth never changes.
    • AI outputs (deal scores, forecasts, ICP insights) live inside Predara, never written back unless you choose to export.
    • No autonomous agents acting on your pipeline. A human is always in the loop.
    • Prompts and model outputs are not used to train third-party foundation models.

    TRU-04

    SOC 2 aligned

    We operate under SOC 2 Type II aligned controls across Security, Availability and Confidentiality, with a Type II audit in progress.

    • Encryption in transit (TLS 1.2+) and at rest (AES-256) on every system.
    • Principle-of-least-privilege access, MFA enforced for all internal accounts.
    • Continuous vulnerability scanning, dependency monitoring and quarterly penetration tests.
    • Documented incident response plan with named on-call engineers and customer notification SLAs.

    ▸ Frequently asked

    Trust questions, answered straight.

    Where is my data stored?+
    Predara runs on enterprise cloud infrastructure inside the UK and EU regions. Backups are geo-redundant within the same legal jurisdiction.
    Who can access my CRM data inside Predara?+
    Only the engineers who actively maintain the platform have production access, and that access is logged. Customer data is never accessed for support unless you ask us to look at a specific issue.
    Do you train AI models on my data?+
    No. We use foundation models in inference mode only. Your prompts, CRM records and generated outputs are not used to train any third-party model.
    How do I delete my data?+
    Disconnect Predara from your CRM at any time to revoke access. To request full deletion of your account and historical data, email support@predara.com and we'll complete it within 30 days.
    Can I get a copy of your security documentation?+
    Yes. Customers and prospects on a paid plan can request our DPA, sub-processor list and security overview via support@predara.com.

    ▸ Read the fine print

    Policies & legal documents

    Got a security question we didn't answer?

    Reach out — we'll get a real engineer or operator on the reply, not a form letter.

    Contact the team