Permissions-aware searchUsers only see results they have access to in the original app. If you can't see a file in Google Drive, you won't find it in Torch. We enforce the same access controls as your connected tools — nothing is surfaced that shouldn't be.
OAuth scopesWe request the minimum necessary permissions for each integration. Read-only access where possible. You can review exactly what permissions are granted during each OAuth flow, and revoke access to any connected app at any time from your account settings.
EncryptionAll data is encrypted in transit using TLS 1.3 and at rest using AES-256. OAuth tokens and credentials are stored in encrypted vaults with strict access controls. Infrastructure is hosted on Google Cloud Platform with SOC2-compliant security practices.
AuthenticationSingle sign-on powered by WorkOS. Supports SAML, Google, Microsoft, and email/password authentication. Team and Enterprise plans include enforced SSO policies and admin controls over user access.
Data handlingWe index metadata and content from your connected apps to power search. We do not sell, share, or use your data for model training. Your data is yours. When you disconnect an app, associated indexed data is deleted within 30 days. Account deletion removes all data permanently.
ComplianceSOC2 Type I certification is in progress. We follow security best practices including regular access reviews, infrastructure monitoring, and incident response procedures. For security questionnaires or compliance inquiries, contact us at [email protected]. Responsible disclosureIf you discover a security vulnerability, please report it to [email protected]. We take all reports seriously and will respond promptly. We ask that you give us reasonable time to address issues before public disclosure.