Skip to content

Everything a security review needs.

The artefacts reviewers ask for, in one place. For enterprise pilots we walk your security team through each of them.

Data flow

What is captured, where it is processed, and the short list of what crosses the network.

Encryption

SQLCipher whole-database encryption, AES-256-CBC with HMAC-SHA512, keyed from the macOS keychain.

Sub-processors

The complete list is below. Neon stores account records, attached feedback diagnostics and organisation records a consultant explicitly publishes. Separately, a cloud AI client a user approves sends its queries and returned snippets to that client's own provider.

Identity model

Magic link or SSO, one active device per user, and automatic sign-out on a new device.

Capture controls

Pause, ignore lists, exclusion categories, and built-in rules for sensitive surfaces.

Operational health

Signed releases, a documented update channel, and separate deletion boundaries for the local store and published organisation records.

Sub-processors, the whole list

Account plumbing, analytics, alerts, downloads, and bookings. The local capture index is never replicated. Neon holds captured-derived content only when you attach a feedback diagnostic or explicitly publish an approved record and its approved source excerpts to the organisation repository.

ServiceWhat it holds
NeonAccount and entitlement records, attached feedback diagnostics, and explicitly published approved records and source excerpts in managed Postgres, UK (London)
StripeBilling and payment details, held by Stripe, not by us
VercelWebsite and account hosting, cookieless analytics, and speed insights; transiently processes submitted feedback diagnostics and explicit organisation-repository publication and retrieval requests before persistent records are stored in Neon
MailjetTransactional email, including magic links and account messages
CloudflareApp download and update delivery (R2); serves release artefacts and sees standard request metadata
SlackOperational alerts for enquiries, admitted-account activity, subscriptions, and existing affiliate obligations; receives the submitted details plus request metadata (page, time, IP address, browser)
CalendlyWalkthrough booking, on Calendly's own pages under Calendly's privacy notice; our booking link also carries the page source and any affiliate-referral tag

Analytics and cookies, per surface

Three surfaces, three postures. The desktop app sends no analytics at all.

Desktop app: No telemetry

No analytics beacons leave the app. Routine account traffic carries sign-in, billing, device registration, and aggregate licence state; an approved record crosses only when the consultant explicitly publishes it.

Marketing site: Cookieless analytics

Vercel Web Analytics and Speed Insights use no cookies or cross-site identifiers. Conversion events never include form values.

Web app: First-party cookies only

Sign-in and security cookies plus short-lived legacy-journey compatibility cookies, with the same cookieless analytics. Nothing is used for advertising.

A pilot shaped for procurement.

Enterprise evaluations run as a 3-month paid pilot for up to 25 users, with SSO, a dedicated account manager, and a security walkthrough at the start rather than the end.

Enterprise pilot
Length
3 months, paid
Scope
Up to 25 users
Identity
SSO, Google or Microsoft Entra ID
Review
Security walkthrough included

Bring your hardest reviewer.

Enterprise enquiryDownload the one-pager (PDF)Read the security overview