Updated May 2026. Reading time: 7 minutes.

AI Fellow Security and Data Handling

How FellowHire handles your data, what your fellow can and cannot see, and why our security model is built for regulated work.

Security is the first question most buyers ask before bringing an AI coworker into Slack or Teams. This page answers it. FellowHire's security controls are built to SOC 2 and ISO 27001 standards, with formal certification in progress. Customer data is encrypted in transit and at rest. Your data is never used to train models. Below is the detail behind those claims.

Compliance posture

SOC 2

Built to standard — certification in progress

ISO 27001

Built to standard — certification in progress

TLS 1.3

Encryption in transit

AES-256

Encryption at rest

FellowHire's security controls are built to SOC 2 and ISO 27001 standards. Everything we have built — infrastructure, data handling, access controls, audit trails — is designed to meet both. Formal certification is in progress.

Hosting. AWS US regions by default. EU-region support available on request.

Model providers. OpenAI and Anthropic models run through Amazon Bedrock inside our own AWS environment. Bedrock does not use customer data to train models and does not share it with the model providers. Customer data is never used to train shared models.

A detailed security-controls summary and our DPA are available to your team during procurement. Reach out via /demo and we will share them under NDA.

What an AI fellow can and cannot see in your stack

Slack. A fellow sees only the channels it is invited to and the DMs sent to its bot user. We default to channel-specific scopes, not workspace-wide.

Microsoft Teams. A fellow operates inside the tenant under Graph permissions granted by the admin. Same principle: minimum scopes for the role.

Connected tools (CRM, helpdesk, accounting, etc.). A fellow gets the integration access the customer grants. We default to read-only and write-on-approval where supported by the upstream tool.

The principle. Scope discipline matters more than any single certification. We default to the minimum scope a fellow needs to do its role and nothing more. Customers control what gets added.

Where your data goes

A fellow receives a message or a connected-tool event in your stack.

The fellow queries a model — OpenAI or Anthropic models, served through Amazon Bedrock inside our own AWS environment.

Outputs are returned to the fellow and surfaced in Slack/Teams or the connected tool.

We retain conversation logs and tool-action logs for the fellow's improvement (default 90 days, configurable per customer).

We do NOT use customer data to train shared models. Each fellow's training corpus is per-customer and stays per-customer.

Because the models run through Amazon Bedrock, your prompts and outputs never leave our AWS environment for the model providers: Bedrock does not use customer data to train models and does not share it with OpenAI or Anthropic.

Audit and review

Every fellow output is logged with timestamp, channel, requester, and the action taken.

Logs are accessible to your admin user via the FellowHire admin panel.

For customer-facing work, default posture is draft-with-review. The human reviewer is logged.

Auto-send categories (where the fellow sends without human review) are configured during scoping and are visible in the admin log.

Audit-trail data export is available on request.

See FellowHire in action for your team

Common security questions

No. Customer data is used to train YOUR fellow only. We do not aggregate customer data into shared training sets. OpenAI and Anthropic models run through Amazon Bedrock inside our own AWS environment, and Bedrock does not use customer data to train models or share it with the model providers.

Our security controls are built to SOC 2 and ISO 27001 standards, and formal certification is in progress. A detailed security-controls summary and our DPA are available to your team under NDA during procurement.

AWS US regions by default. EU-region support available on request.

Default 90 days. Configurable per customer down to 30 days. We honor data deletion requests under GDPR and CCPA principles.

Yes. We share a detailed security-controls summary and our DPA under NDA during procurement.

We have an incident-response process. We notify affected customers within 72 hours of confirmed material incidents. We publish post-mortem summaries for any incident affecting more than one customer.

Built for regulated work

Law firms, accounting firms, and other regulated industries have specific security and data-handling requirements. FellowHire's compliance posture, scoped access model, and audit trails are built to meet them.

For industry-specific detail, see /industries/law-firms, /industries/accounting-firms, and /industries/ecommerce-brands.

For specific data-residency, retention, or deployment requirements, we scope those during onboarding. Reach out via /demo.

← See all guides

Need the detailed compliance documentation?

If your team needs a security walkthrough, a detailed security-controls summary, or a conversation with your InfoSec team, just ask. We share it all, including our DPA, under NDA during procurement.