Security
How Darwin protects your workspace, your visitors’ conversations and your connected calendars, and where to send a security report.
Updated 2026-10-01Where your data lives
Darwin’s app runs on Railway in the United States, and your workspace data sits in a Supabase Postgres database, also in the US. Supabase encrypts that database at rest and backs it up daily. Cloudflare serves this website and our documentation.
Encryption in transit
Every connection to Darwin is encrypted with TLS: the app, the chat on your website and the APIs behind them. Ask over plain HTTP and you get redirected to HTTPS; the app also turns away the old TLS 1.0 and 1.1 protocols. And each time our servers connect to the database, they check its certificate first.
Calendar and meeting connections
When you connect Google Calendar, Calendly, Zoom or Webflow, the access tokens are encrypted with AES-256-GCM before we store them, and each one is tied to its own workspace and connection. Your RevenueHero webhook secret gets the same treatment. None of these tokens is ever sent to your browser, and disconnecting an integration deletes them.
Signing in
You sign in with a verified email address and a password of at least 12 characters, or with Google, which shares only your email address and basic profile. Supabase Auth handles passwords, so Darwin doesn’t store them. Sessions run on secure, HTTP-only cookies, and repeated failed attempts on one account are throttled.
Workspace access
Your workspace’s data lives in its own database schema, and Darwin confirms you’re a member on every request before it reads any of it. Who can change what is up to you. Make someone a member and they can look but not edit. An admin can also edit the assistant and connect integrations, and only owners handle billing and invitations.
The chat on your website
The chat widget answers only on the domains you add to your workspace; a request from any other site is refused. It sets no cookies. Once a visitor sends a first message, their browser keeps a conversation ID in local storage, and it expires six hours after they were last active.
AI answers
Answers come from language models that Darwin reaches through OpenRouter. To write one, the model gets the visitor’s message, the page they were on and the parts of your business knowledge that matter for the reply. We don’t train AI models on your data.
Payments
You pay through Stripe’s own checkout page and billing portal, so your card details go to Stripe and never touch Darwin’s servers. What we keep is the billing side of things: subscription status, invoice references and usage records.
Service providers
If your security team asks who else handles data, these are the companies behind the core service. Railway hosts the app and Supabase runs sign-in and the database, while Cloudflare delivers this website to you. Resend sends your account emails and Stripe takes payments. Firecrawl reads your site when you set up the assistant, and OpenRouter is how we reach the AI models.
Keeping and deleting data
Your workspace data, conversations included, stays until you ask us to delete it; nothing expires on a timer. To close your account or remove a workspace, email ari@meetdarwin.ai and we’ll tell you what can go and what billing records we have to keep. Copies in backups age out on the normal backup cycle.
Reporting a security issue
Found a vulnerability? Email ari@meetdarwin.ai with what you found and the steps to reproduce it, and please give us a chance to fix it before you share it publicly. Security questionnaires and requests for more detail go to the same address.