We recently got our CASA Tier-2 compliance done (Cloud Application Security Assessment). We've also gone through Google's OAuth compliance process for every new integration we add that's related to Google. These assessments scan our app and make sure that our software meets pretty stringent standards when it comes to data security and encryption, and that we're not using the data for anything other than the specific features we promise (i.e. not sharing or selling to advertisers, etc.). You can read more about CASA here (https://appdefensealliance.dev/casa). We haven't gone through SOC2 yet, but planning on soon once we have a few more integrations.
Does personal information get sent to OpenAI or Claude as part of the functionality? Can users request deletion of their data, and if so, what is the process? Are there specific protocols in place to ensure security? (i.e. Do you use encryption at rest?).
Unless you intend to personally audit their code, I'd argue it couldn't possibly matter. Even businesses like Apple publish all kinds of documentation that belies the reality of their infrastructure. The iMessage Security Overview doesn't mention the NSA's retention period for encrypted communique; the push notification documentation doesn't tell you about the government middleman processing each alert.
You either trust people blindly, or you validate them personally. Getting a pinkie-promise about privacy from the CEO is worth absolutely nothing in real-world security terms.
So... in Apple's own words, they are allowed to cherry-pick who's allowed to read their code and audit their privacy, in the same way they strategically deny researchers the ability to audit certain iOS features.
You're still taking them on their word, here.
[0] https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...
The measurement logs will be publicly available.
As you develop your messaging, I wanted to share the questions I had as I think a lot of users will ask the same:
1. What powers Martin? Is it a custom LLM or powered by OpenAI, Anthropic? 2. Is any of my data ever used in training? 3. Will I always be notified before new texts / calls / actions are taken on my behalf? Does the AI present as me or are my contacts aware that it's an AI assistant that may provide incorrect information? 4. Can I easily and quickly remove all my data and context?