Last updated: February 2026

Security Policy

Performy's primary priority is the security of customer data. This document details our practices to ensure the Confidentiality, Integrity, and Availability of information.

1. Infrastructure and Certifications

Performy's primary application and database infrastructure is hosted on Amazon Web Services (AWS) in the European Union (Ireland, eu-west-1), which maintains leading security certifications (SOC 1/2/3, ISO 27001, ISO 27018) for the underlying cloud infrastructure. Certain specialized service providers may process specific data outside the European Union where necessary to provide the service, subject to appropriate contractual and data protection safeguards. Payments are handled externally by Stripe (PCI-DSS compliant); Performy never stores card data.

2. Storage and Hosting (Ireland)

3. Encryption and Connectivity

Google Calendar data security. Google Calendar data accessed by Performy is handled using least-privilege, read-only OAuth access through the calendar.events.readonly scope. Performy does not use Google Calendar data for advertising or for training general AI/ML models. Data transmitted to Performy is protected using HTTPS/TLS, and stored data is encrypted at rest. Access to customer data is restricted using role-based, least-privilege access controls. When third-party infrastructure is required to provide the notetaker functionality, those providers process data only to the extent necessary to provide the requested service, and under appropriate contractual and data-protection safeguards.

4. Monitoring and Authentication

5. Bring Your Own Key (BYOK)

For customers with elevated privacy requirements, Performy can operate with your own AI credentials (OpenAI or Google Gemini).