Security

Last updated: 11 August 2026 Version 1.0 Status: pilot

This page describes how Othersmind (operated by NUL TECHNOLOGY, 202603148027 (003857548-W)) actually protects customer data. Every control listed here exists in the running code today. We also say plainly what we have not built yet — we would rather publish an honest gap than a claim we cannot defend.

Access and authentication

Gmail: least privilege by design

AI agents: human approval before any external action

Data protection

What we are still building

We publish this list because honest gaps protect customers better than claims we cannot defend:

  • Encryption at rest for OAuth tokens. Stored Gmail OAuth tokens are protected by access controls, transport encryption and our database provider's managed protections, but are not yet encrypted at the application level. This is on our engineering roadmap. Customers can invalidate stored tokens at any time by revoking access in their Google Account.
  • Formal tenant isolation. Customer data is separated by project-level access control within a shared database. Formalised per-tenant isolation is planned as the customer base grows.
  • In-product deletion and automated retention. Deleting synced email data currently requires an emailed request (see Privacy Policy §12); automated retention schedules beyond our 90-day agent-findings purge are planned.

We do not hold ISO 27001, SOC 2 or similar certifications, and we make no compliance claims we cannot verify.

Reporting a vulnerability

If you believe you have found a security vulnerability in Othersmind or othersmind.ai, please email chiewaylee@gmail.com with the subject line "SECURITY". Include steps to reproduce and, if possible, the affected URL or endpoint.