trust ▸ compliance TRUST

Compliance is a feature, not fine print.

GDPR-aligned controls, a Data Processing Addendum, data export and erasure, documented sub-processors - and we don't claim certifications we don't hold.

Writ runs on your own accounts, with your own credentials and data, on sites you are authorized to use.
compliance ▸ gdpr 01

GDPR-aligned by design

We align our controls with the EU General Data Protection Regulation. You own your data, you can take it with you, and you can have it erased. We act as a data processor for the content you automate and as a data controller for your account and billing data.

  • Right to access & portability: export your account data from Settings.
  • Right to erasure: delete your account or organization; deletion cascades across tenant-scoped resources.
  • Lawful basis & consent: you are responsible for a lawful basis on the data you collect; we honor consent and erasure requirements.
  • Data minimization: secrets are encrypted at rest and never returned by the API, shown to the AI, or written to logs.
compliance ▸ dpa 02

Data Processing Addendum

We offer a Data Processing Addendum (DPA) that sets out how we process personal data on your behalf, the security measures in place, and the sub-processors we rely on. Request the current version for your organization, or read the published terms.

compliance ▸ certifications 03

What we hold

GDPR alignment

In place

Data rights, DPA, sub-processor transparency, and erasure are available today.

Encryption & isolation

In place

Secrets encrypted at rest, strict tenant isolation, and least-privilege access across every run.

We don't over-claim. We do not display certifications we do not hold. If you need a current security review,contact our team.
compliance ▸ data handling 04

How your data is handled

  • Sensitive material (passwords, 2FA seeds, vault secrets, tokens, sessions) is encrypted at rest with the platform key.
  • Every record is tenant-scoped and filtered at the data layer; no cross-tenant access.
  • Marketplace recipes are stripped of creator credentials at publish - every run uses the installer's own data.
  • Run logs redact secrets; resolved values exist only inside a single run.
compliance ▸ faq 05

Compliance questions

Is Writ GDPR compliant?
We align our controls with the GDPR. You can export and delete your data, we offer a Data Processing Addendum, we document our sub-processors, and we honor erasure and consent requirements. We act as a data processor for the content you automate and as a controller for your account data.
Do you have a DPA I can sign?
Yes. We offer a Data Processing Addendum. Contact us to request the current version for your organization.
What is your certification posture?
We build to recognized security and privacy standards and align our controls with GDPR, but we do not claim certifications we do not hold. If you need a current security review, contact us.
How do I request data export or deletion?
You can export your account data and delete your account or organization from Settings. Deletion cascades across tenant-scoped resources. For data-subject requests on behalf of others, contact us.
Where is my data processed?
Writ relies on a small set of sub-processors for infrastructure, payments, and communications. See our sub-processors page for the current list and the role each one plays.
compliance ▸ close 06

Need our compliance documents?

Request a DPA, ask about our data controls, or get a current security review.