Security

We ask for less
than you expect

To do this job properly, Ghostseats needs to see what you pay for and who signs in. It does not need to see anything else, and it does not have the ability to change anything. That is a deliberate design decision, not a limitation we are apologising for.

A wall of dark frosted glass with a cold mint light glowing behind it — something seen clearly but never touched.

No access to your systems

Ghostseats holds no credentials for any of your tools. It cannot deprovision a user, cancel a contract or change a licence, because it was never connected to anything that could.

Numbers, not people

What you enter is a seat count and a price per tool. No names, no email addresses, no files, messages or calendars — nothing about any individual member of staff.

Encrypted in transit and at rest

TLS on every request, encryption at rest for the licence records you enter. Documents you upload are read for their text and never stored.

Audit trail

Every proposed cut keeps who suggested it, the evidence behind it, who approved it and when it was actioned.

Where we actually are

SOC 2 Type II is in progress, not finished

We are mid-audit. We are not going to put a badge on this page until it is real. If your security team needs the current status, the controls we have implemented, or a questionnaire completed, ask and we will send you exactly where we are — including the gaps.

If you need a certification we do not hold yet, we will tell you that instead of talking around it.

[email protected]

Straight answers

The questions
security teams
always ask

Usually in this order, usually on the second call. Here they are in advance.

A pane of dark glass lit from behind with cold mint light — reading through the glass without reaching past it.
What access do you actually need?
None. Ghostseats does not connect to your systems at all — you bring the invoices, and you enter the usage counts. There is no integration for a security team to review, because there is nothing to grant.
Can Ghostseats cancel something by itself?
No, and it is built so that it cannot. It produces a recommendation with evidence attached. A person in your company actions it in the vendor's own admin panel.
Do you read our documents or messages?
Only the invoice or statement you choose to upload, and only to pull the subscription lines out of it. Its text is read on our server, never stored, and nothing inside the tools themselves ever reaches us.
Who owns the data?
You do. Your spend, your usage and your vendor terms are yours. We do not sell them, and we do not pool them with other customers.
Where is it hosted?
In a major cloud provider's regions, with Canadian data residency available for customers who need records kept in country.
What happens if we leave?
You export in a documented format, we revoke our own access, and we delete on a defined schedule and confirm when it is done.

Send us your
security review

We would rather answer it now than three months into an implementation.