Security

We ask for less
than you expect

To do this job properly, Ghostseats needs to see what you pay for and who signs in. It does not need to see anything else, and it does not have the ability to change anything. That is a deliberate design decision, not a limitation we are apologising for.

A wall of dark frosted glass with a cold mint light glowing behind it — something seen clearly but never touched.

Read-only, always

Ghostseats requests read scopes and nothing else. It cannot deprovision a user, cancel a contract or change a licence, because it was never given the ability to.

We do not read content

We read who has a seat and when they last signed in. Not their files, their messages, their calendars or anything they wrote.

Encrypted in transit and at rest

TLS on every connection, encryption at rest for billing records and usage data. SSO and SCIM on enterprise plans.

Audit trail

Every proposed cut keeps who suggested it, the evidence behind it, who approved it and when it was actioned.

Where we actually are

SOC 2 Type II is in progress, not finished

We are mid-audit. We are not going to put a badge on this page until it is real. If your security team needs the current status, the controls we have implemented, or a questionnaire completed, ask and we will send you exactly where we are — including the gaps.

If you need a certification we do not hold yet, we will tell you that instead of talking around it.

[email protected]

Straight answers

The questions
security teams
always ask

Usually in this order, usually on the second call. Here they are in advance.

A pane of dark glass lit from behind with cold mint light — reading through the glass without reaching past it.
What access do you actually need?
Read access to billing or expense data, and read access to your identity provider for sign-in activity. That is the whole list, and we will scope it down further if your security team wants.
Can Ghostseats cancel something by itself?
No, and it is built so that it cannot. It produces a recommendation with evidence attached. A person in your company actions it in the vendor's own admin panel.
Do you read our documents or messages?
No. We read licence assignment and last-login timestamps. Nothing about the content inside those tools ever reaches us.
Who owns the data?
You do. Your spend, your usage and your vendor terms are yours. We do not sell them, and we do not pool them with other customers.
Where is it hosted?
In a major cloud provider's regions, with Canadian data residency available for customers who need records kept in country.
What happens if we leave?
You export in a documented format, we revoke our own access, and we delete on a defined schedule and confirm when it is done.

Send us your
security review

We would rather answer it now than three months into an implementation.