What CoDesk can and cannot do

You are being asked to connect your books, your client conversations and your project data to something that reads them. That deserves a straight answer about what it can see and what it can touch.

It cannot change your systems

This is the part worth understanding properly, because it is not a permission setting that someone could switch on by accident.

The model that reads your records and writes the answer is given no tool that can write anywhere. It can only produce a draft. Creating anything runs through a separate path that requires a person to press Apply, and that path records who pressed it and when. There is no configuration in which CoDesk writes to a system on its own, because the ability was never built into the part of the system that decides things.

In practice that means: it can draft a Jira ticket for you to approve. It cannot edit an existing ticket, send a message, move money, or touch your accounting records at all. QuickBooks in particular is read-only, with no write path even behind approval.

It only sees what you already see

Every connection uses credentials you supply, scoped to what those credentials can reach. Connecting a tool to CoDesk does not widen anyone’s access to it. If a project is invisible to the account you connect, it is invisible to CoDesk, and to everyone asking questions through it.

For Slack that means named channels rather than the whole workspace: private channels stay private unless you deliberately add them, and you can remove one at any time.

One workspace cannot see another

Separation between customers is enforced in the database, not only in the application, so a bug in a page cannot leak across it. Every query is scoped to the workspace making it.

Every answer keeps its working

CoDesk records what it was asked, which sources it chose, what it read, and what it answered. That log is not decoration: it means a figure someone acted on three months ago can still be taken apart, and it means an approved action always has a name against it.

It is also why CoDesk will say it does not know. If your tools have nothing to say on a question it tells you that, rather than producing something plausible. An answer with no record behind it is worse than no answer.

Your data is not training anything

Your business data is not used to train models, ours or anyone else’s. It is read to answer your question and that is the end of its job.

Who else touches it

Running CoDesk means passing data through a small number of other services. We would rather list them than describe them vaguely:

  • Supabase — the database, and sign-in.
  • Anthropic — the model that reads retrieved records and writes the answer.
  • Voyage AI — turns messages and transcripts into a searchable form.
  • Vercel — hosts and serves the application.

Plus the tools you choose to connect, which you already have your own relationship with. The privacy page covers what each holds.

What is fresh and what is stored

Project and accounting records are fetched at the moment you ask, so they cannot be stale and we are not holding a copy. Messages and transcripts are indexed, which means we do hold a processed copy, because searching them by meaning is the only way “where did we land on that” ever works.

Sign-in

Three ways in: Google, an email and password, or a one-time link sent to your address. Credentials for connected tools are stored encrypted. There is no shared login for a workspace — people are invited individually, so removing someone removes their access.

What we have not done yet

Two of these are intentions, not facts, and we are not going to blur the line.CoDesk does not currently hold SOC 2 or ISO 27001 certification. We also have not published a formal breach-notification window. If either matters for your sign-off, ask us where it stands rather than assuming from this page.

Still have a question?

Security questions get a real answer from a person, not a questionnaire response. Ask us.