Trust

Built so you can be honest about your team

A useful conversation about a team involves saying things you would never put in an email — that someone is stretched, that a colleague is in the way, that you're not sure a strong performer is actually the problem. That's the risk this page is about, and it's the one we designed for first.

What we need to know about your company

Not your company name. It's optional, nothing asks twice, and the questions are the same either way. What changes the wording is the context: what you lead, roughly how big the company is, who owns it, and what you have been asked to deliver — and all of that is optional too. A read on a team of ten looks nothing like a read on five thousand, which is why we ask about the structure rather than the identity.

If you do give the name, we use public sources — the Norwegian company register and similar — to sharpen the guidance. That's your choice, not a requirement.

We don't connect to your systems. No HR system integration, no calendar access, no mailbox access, no document upload. Ygora reasons over what you choose to tell it, which means the amount of company data at risk is bounded by what you typed.

What happens to what you say about a named person

This is the question that matters, so here are the mechanisms rather than reassurances.

  • It never appears in an email. Ygora emails are a doorway, not a briefing: they say something is waiting and link to it. No plan text, no names, no numbers, and nothing in the subject line — a subject line shows on a lock screen. This is enforced in the code, not by policy: the function that sends those emails accepts no plan, team or name parameters at all, so a future feature cannot quietly pass “just a little” context.
  • It is never reused for another leader. We do not cache or share answers between customers. A reply is specific to one team; serving it to someone else would be both useless and a leak.
  • It is never used to train a model. Not ours, and not our providers'.
  • Nothing here asks you about a named person. Every question is about what exists and who owns it, so the answers attach to a role rather than to somebody. And where we keep a record of what Ygora wrote back — to learn which kinds of guidance actually help — we store the outcome against a one-way hash of the text, never the text itself.
  • The specifics stay behind sign-in. Your stress tests, the documents drafted from them and your bench are visible only to you when you're logged in. Per-leader by default: a colleague at the same company does not see your workspace.

One thing we ask of you in return: don't enter health information, union membership, or anything else in the special-category bracket about a team member. Ygora doesn't need it to be useful, and we'd rather it never arrived.

Who processes it, and where

Encrypted in transit and at rest. A short, named list of providers, and no others:

  • Supabase — database and sign-in, hosted in the EU.
  • Anthropic — the model that drafts your documents and answers you in the conversation. It never produces the findings or the summary: those are computed from your answers. Processed in the United States. Not used for training.
  • Vercel — application hosting. United States.
  • Resend — delivery of sign-in and service emails, which carry no team content.

Where data goes outside the EU/EEA we rely on the EU Standard Contractual Clauses. We do not sell personal data, we run no advertising or third-party tracking cookies, and we share nothing beyond the providers above except where the law requires it. Ygora AS is the data controller throughout; the full legal detail, including your GDPR rights and how to exercise them, is in the privacy policy.

Getting your data out. Download everything, or delete the account outright, from Settings — you do it yourself, in the product, and neither goes through us. No support queue, no retention offer. If you would rather ask a person, hello@ygora.ai reaches a founder.

What we don't have yet

We're a small Norwegian company and we'd rather tell you this than have you find out in a procurement form. Ygora does not currently hold a SOC 2 report or ISO/IEC 27001 certification. We haven't started an audit, and we won't claim a badge we don't have.

What we do run is on this page: data minimisation by design, a short named subprocessor list, encryption in transit and at rest, multi-factor access to production, per-leader isolation, and the structural limits on email and reuse described above. If your organisation needs a formal audit before you can buy, tell us — it moves up the list when a real customer needs it, and we'll be straight with you about the timeline rather than promising a quarter.

We'll sign a data processing agreement, answer a security questionnaire, and talk to your IT or legal team directly. Email hello@ygora.ai and it reaches a founder, not a queue.

Questions we haven't answered here go straight to us.

Email hello@ygora.ai

Or book 30 minutes with a founder.