Written for the person who has to say yes.

What Couldi applies while a project is built, what it records, where your data sits, and what we don’t claim. In plain terms, so your security team can read it once and decide.

Security audit

A security audit on your criteria.

Couldi runs an automated security audit that pairs fixed checks with an AI review against a maintained catalog of security criteria. On Pro, org admins choose the criteria and run the audit, and its results are recorded with the project.

Governance

Your organization sets the rules.

Admins define org-wide policies that apply to every build and every user — no per-project configuration required. Usage limits can be set one-time or monthly, for one person or as a default for every member. Role-based access and invite-only membership controls mean you decide who is in and what they can do.

Org-wide policies

Set once. Applied to every build, for every user.

Per-user limits

One-time or monthly caps, per person or as a default for every member.

Role-based access

Admin and member roles — distinct capabilities per role.

Invite-only membership

You control who joins. No open sign-up for your org.

Audit trail

A record of who ran what.

The audit trail records the AI chats, agent runs, deploys, security audits and GitHub pushes on every project: who ran each one, and when. Org admins can review each project’s trail.

Data handling

Plain facts about your data.

US hosting

Couldi is hosted in the United States.

Isolated project workspaces

Project code is stored in per-organization workspaces — one org's projects are not accessible to another.

Account data in Google Firebase

User account data is stored in Google Firebase.

Payments by Stripe

Card payments are processed by Stripe. Card data never touches Couldi's servers.

Self-hosted analytics

Our Matomo analytics set no cookies and respect the Do-Not-Track header. The one first-party cookie we set before you sign in records which link first brought you here; our Privacy Policy explains it.

Full legal terms in-app

Terms of Service, Acceptable Use Policy, and Data Processing Agreement are available in-app to every user.

Honesty

What we don't claim.

We're an early-stage product in limited early access. Our security audit is aligned to criteria from OWASP ASVS, GDPR, PCI DSS, HIPAA, and SOC 2 — but we won't wave certifications we don't hold. Ask us anything directly and we'll show you exactly how it works.

Put your security questions to us directly.