Common Ground
monthly team check-ins
Security & data handling

What we store, who touches it, and what the system will not do.

Candid answers depend on a promise people believe. This page describes how that promise is enforced in the product, not just stated in a policy.

Anonymity is enforced by the architecture

Most feedback tools treat anonymity as a setting an administrator can change. Here it is a property of how the system is built, which means there is no toggle — for us or for your managers — that quietly undoes it.

One limitation worth stating plainly, because no product can engineer it away: if someone writes something only they could have written, a manager who knows the team may still guess. We protect the record, not the distinctiveness of what a person chooses to share. We say so on the response screen too.

What we store

What we do not store

Access and authentication

Infrastructure

Sub-processors

These third parties process customer data on our behalf in order to deliver the service.

ProviderPurposeData involved
VercelApplication hosting and content deliveryRequests to the service
Neon (via Vercel Postgres)Database hostingAll stored service data
AnthropicGenerating the monthly brief from pooled responsesPooled, code-labelled check-in responses
ResendSending check-in invitations and monthly briefsRecipient email addresses and message content

Responses sent to Anthropic for brief generation are pooled and carry only anonymous codes. They are sent through the commercial API, which does not train models on submitted data.

How the AI is used

Once a month, the pooled responses for an organization are sent to Anthropic's API with a prompt that returns a structured brief. The output is a summary, not a judgment: it can be wrong, it can miss nuance, and it should never be the sole basis for a decision about any individual. Treat it as a prompt for a conversation.

Retention and deletion

Data is retained while an organization is active. On request, or when an organization is closed, we delete it along with its departments, roster, responses, and briefs. Backups held by our infrastructure providers roll off on their own schedules. Full detail is in the privacy policy.

Current certification status

We do not hold a SOC 2 report today, and we would rather say so than imply otherwise during procurement. If a formal attestation is a requirement for your organization, tell us as part of your evaluation and we will discuss where it sits on our roadmap.

Reporting a vulnerability

Email admin@roadcommand.co with the detail and we will acknowledge it. Please give us a reasonable window to fix anything you find before disclosing it publicly.