Security at Supercomms
Built to protect the communication and context you trust Supercomms with.
Last updated: September 10, 2026
Supercomms helps you turn important communication into clear priorities, decisions, and actions. To do that, we process communication and context that can be among your most sensitive business data. We do not take that responsibility lightly.
This page explains, in plain terms, how we protect your data and build security into Supercomms. If anything here is unclear, or you need more detail for a security review, contact us at security@supercomms.io.
Our principles
Only what’s needed. Supercomms requests only the permissions needed to provide the features you choose to use. Access to your communications is requested separately from sign-in, and permissions can be removed at any time in Settings.
Processed by machine, not read by a person. Your communications are processed automatically to provide Supercomms. Our team does not routinely read your messages. Human access is restricted to exceptional cases, such as when you request support, to investigate a security issue, or when legally required. Your data is never sold or used by Supercomms to train AI models.
Encrypted, and kept to a minimum. We minimize what we store. Data is encrypted in transit and at rest, and retained only for as long as needed to provide the product or meet legitimate operational and legal requirements. After that, it is permanently deleted.
Yours to remove. Disconnect an account or delete everything, at any time, with just a few clicks in Settings.
Accounts and sign-in
Sign in with Google — no passwords, ever
Supercomms has no passwords. You sign in with Google, so your credentials are only ever handled by Google, never by us. We never see, store, or process a password. There is nothing for us to lose. Because sign-in runs through Google, your account is protected by the multi-factor authentication you have set up on your Google account — including any hardware keys or passkeys.
Sensitive actions ask you to confirm it’s really you
Before anything irreversible — such as deleting your account — Supercomms sends you back through Google to re-confirm your identity. A stolen session alone is not enough to take a destructive action.
Sessions expire
Your sign-in session is held in an encrypted, tamper-proof cookie that your browser cannot read from JavaScript. Sessions last at most 24 hours before they must be renewed, and a session left idle simply expires. Signing out clears it immediately.
Encryption
In transit
Every connection to Supercomms uses modern TLS — version 1.2 or 1.3 only, with older and weaker protocols refused. Our public endpoint holds an A+ rating from Qualys SSL Labs, the industry-standard independent test. Traffic is forced to HTTPS and protected by HSTS.
At rest
Your email content, the OAuth tokens that reach your mailbox, and other sensitive fields are encrypted in our database using AES-256-GCM — authenticated encryption that both hides the data and detects any tampering. If a key is ever missing or invalid, the system refuses to fall back to storing anything in plain text.
Your data and AI
No person reads your email
Supercomms uses AI to sort, summarise, and draft — automatically, and only to carry out what you have asked it to do. That work is done by machine. No person at Supercomms reads your inbox.
Never used to train AI
To process a request, relevant content is sent to trusted AI providers, and then the work is done. We have confirmed with every provider we use that your content is not used to train their models on the plans we operate. Our current AI and processing providers — our sub-processors:
OpenAI — Classification and drafting
Google (Gemini) — Classification and drafting
Groq — Fast draft assistance
AssemblyAI — Voice transcription, only if you use voice
We keep only what we need
Your email lives in Gmail; Supercomms is a layer on top, not a second copy of your inbox. We keep a working set to make the product fast, and we age out older message content on a rolling basis rather than holding it indefinitely.
How the application is built
Security is enforced on our servers, not in the browser, so it cannot be bypassed by tampering with the page:
Strict Content-Security-Policy. The browser is told exactly what code may run, blocking injected or third-party scripts. Cross-site request forgery protection. Every state-changing action requires a per-session token, checked on the server. Isolated email rendering. Untrusted email content is displayed inside a locked-down sandbox with scripts disabled, so a malicious message cannot reach your account. Rate limiting. Automated abuse is throttled per account and per network address. Dependency hygiene. Third-party components are pinned and monitored, and we address known vulnerabilities as part of our release process.
These controls are not only self-declared: each was assessed against the CASA requirements by an independent laboratory, alongside automated dynamic scanning of the running application.
Your control over your data
Disconnect anytime. Removing an account revokes our access to it at Google immediately — the permission simply no longer exists.
Delete your account. Deletion revokes access at Google and stops all processing right away. Your data is then permanently erased after a 30-day recovery window, in case the deletion was a mistake.
Nothing hidden in your browser. We do not stash tokens or message content in browser storage; your session is the single encrypted cookie, and signing out clears it.
Independent validation
We believe security should be checked by people other than us. Supercomms has completed the App Defense Alliance Cloud Application Security Assessment (CASA) at Assurance Level 1, assessed by TAC Security — an independent third-party laboratory authorised by the App Defense Alliance to conduct CASA assessments.
STATEMENT OF VALIDATION
ADA Cloud Application Security Assessment
Assessed by
TAC Security
Assessment type
AL1 (Lab Tested, Lab Verified)
Certification ID
1bb99cc7
Issued
September 5, 2026
Valid through
September 6, 2027
Status
Complete, in compliance
CASA is built on the OWASP Application Security Verification Standard. Every applicable control was assessed and passed: Authentication, Session management, Access control, Communications, Data validation, Configuration.
Supercomms is also Google OAuth-verified for the sensitive Gmail permissions it uses — Google reviews both the permissions we request and the independent validation above before granting them. Validated by others, not just declared by us.
Reporting a vulnerability
At a glance
Sign-in
Google OAuth only, no passwords stored
Multi-factor
Enforced by your Google account
In transit
TLS 1.2 / 1.3 only, SSL Labs A+, HSTS
At rest
AES-256-GCM authenticated encryption
Sessions
Encrypted cookie, 24-hour maximum lifetime
AI training
Your content is never used to train models
Data location
Gmail is the source of truth; minimal retention
Deletion
Revoke and stop processing now; erase after 30 days
Validation
ADA CASA AL1, TAC Security, ID 1bb99cc7, to September 2027

