For business buyers
Trust & Security.
Last updated: June 11, 2026
Everything a buyer's security and procurement team needs, in one place. For anything not covered here, email james@modulustech.ai and we will respond quickly.
How your data is handled
- Access control. Every customer record is isolated at the database level, so one account can never read another account's data.
- Encryption. Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers.
- AI content. Material you process in Modulus Studio is used only to produce your output. It is not sold, and our metering layer never stores the content of your sources or drafts.
- Secrets. Provider keys and payment secrets live only on the server side, never in the desktop app or the browser. The desktop app keeps your session token in your operating system's secure store.
- Payments. Card data is handled entirely by Stripe; Modulus never sees or stores full card numbers.
Documents
- Sub-processor list: every third party that can touch your data, what it does, and where it operates. We give 30 days' notice before adding a new one.
- Privacy Policy and Terms of Service.
- Data Processing Agreement (DPA): available for signature on request. Email us and we will send the current version.
- Security questionnaire: we are happy to complete your standard questionnaire (CAIQ or similar) under NDA.
Roadmap
SOC 2 Type 2 (Security): on our roadmap as we move upmarket. In the meantime we lead with the DPA, the sub-processor list, and a completed security questionnaire for due diligence.
Contact
Security or compliance questions: james@modulustech.ai.