Skip to main content
Modem connects to your team’s communication and development tools to aggregate user feedback. That means we handle your data carefully. This page explains what we do to keep it safe.
Full policy documents are available on request. Contact support@modem.dev for compliance documentation.

Compliance

Modem is SOC 2 Type II certified. Visit trust.modem.dev to request our report and review our security posture.

Data Protection

  • Encryption. All data is encrypted at rest and in transit using TLS 1.2+. This covers messages, user profiles, and any files Modem processes.
  • Access controls. Employees only access customer data when there is a documented business need. All production access requires multi-factor authentication and is logged.
  • Assessments. We run quarterly vulnerability scans on public-facing systems and annual penetration tests by independent firms.

Data Access and Sharing

No third-party data sharing. We do not sell or share your data with third parties for their own purposes. Data is only shared with service providers necessary to operate Modem.

Technical Safeguards

  • Tenant isolation. Every database query is scoped to your organization. The Modem Agent reads your data through a read-only role that PostgreSQL Row-Level Security limits to your organization’s rows.
  • Token encryption. OAuth tokens from connected services (Slack, GitHub, Linear) are encrypted at rest using AES-256-GCM with per-token initialization vectors before being stored in the database.
  • Signed media URLs. When Modem proxies images or files from third-party services, it uses HMAC-SHA256 signed URLs with time-limited expiry. The signature covers the encoded source location, so the URL can’t be altered, and the credentials needed to fetch private files stay on Modem’s servers.
  • Webhook verification. Modem checks each inbound webhook against the provider’s signature or shared secret before processing it. GitHub and Linear webhooks are verified with HMAC-SHA256 signatures and constant-time comparison.
  • Minimal access. Integrations with third-party services only request the scopes necessary for the product to function.
  • Input validation. All API inputs are validated against strict schemas at the boundary before reaching application logic.

Data Retention

  • While your organization exists. We retain your data for as long as your Modem organization exists.
  • After cancelling a paid plan. Cancelling moves your organization to our free tier. Your data is retained so you can keep using Modem or resubscribe; it is not deleted by cancellation alone.
  • On deletion. Owners can delete the organization by typing its name to confirm. It disappears from Modem right away. After a 24-hour grace period, Modem begins permanently removing its data from our production database. You can also request deletion at any time — see below.
  • Backups. Deleted data is purged from encrypted backups within 90 days and is never restored into production.

Requesting Deletion

You can request deletion of your data at any time by emailing support@modem.dev with the subject “Data deletion request”. Tell us the scope: your whole organization, a connected workspace, or a named individual. We verify that the requester is authorized within 2 business days, complete the deletion within 3 business days of that verification, and confirm in writing what was deleted and when. Requests are accepted from an admin of the Modem organization, an admin of the connected workspace, or the individual whose data is the subject of the request.

Incident Response

If we discover a security incident affecting your data, we notify you as soon as reasonably possible with details about what happened and what we are doing about it. We comply with all applicable breach notification laws. After any incident, we conduct a review to identify root causes and prevent recurrence.

Reporting a Vulnerability

If you discover a potential security vulnerability, report it to security@modem.dev. We appreciate responsible disclosure and do not take legal action against researchers who act in good faith.