Security at Annie
Annie is a small, founder-run company, and this page is written on the assumption that you would rather read what is true than what sounds impressive. Where a control exists, it is described exactly. Where one does not exist, it says so and says what is done instead. Section 4 is the one to read first if you are evaluating us.
1. Where your data lives
Your account data sits in a Supabase Postgres database hosted in Supabase's ap-northeast-2 (Seoul) region, with uploaded files (CVs, right-to-work scans, company documents) in Supabase storage alongside it. The application and its server-side functions run on Netlify. Connections are encrypted in transit, and both providers encrypt data at rest.
Seoul is outside the UAE and outside the UK, so using Annie involves an international transfer of personal data. That is covered in section 7 of the Privacy Policy, and it is a deliberate fact to put in front of you rather than in a footnote: if your firm has a data-residency requirement that names a specific country, Annie does not meet it today.
Separation between customers. Annie is one database shared by all customers, with row-level security doing the separating. Every one of the 93 tables in the database has row-level security enabled. 63 of them carry policies that scope each row to the account or team that owns it; the remaining 30 carry no policy at all, which under Postgres means no customer session can read them by any route — those are Annie's own operational tables (usage meters, caches, webhook logs, market research) and contain no customer CRM records. Your contacts, candidates, companies, notes, documents and invoices are all in the first group.
Intelligence signals are private to the individual user even inside a team, because two recruiters at one firm generally work different markets.
2. Who else processes it
Who processes data for Annie, and what each provider receives, is the table in section 4 of the Privacy Policy. That table is the list. It is kept in one place so a second summary here cannot drift out of date. If a provider is added or replaced, that table is what changes.
3. Who at Annie can see your data
Annie is operated by one person, the founder, who has administrative access to the production database and could in principle read any row in it. Pretending otherwise would be dishonest, and any vendor of this size telling you differently is describing an aspiration.
What is true is that the product gives no screen that does it. The admin area inside Annie is built on a fixed set of read-only aggregate queries, gated server-side on an is_admin flag, and they return account and billing metadata only: firm name, account email, plan, subscription status, seat counts, renewal dates, discount codes, usage totals, error counts, and support requests you have sent us. No admin screen reads your contacts, candidates, companies, notes, documents or mailbox content, and none of those tables is reachable from the admin area at all.
Direct database access is used for operational work such as diagnosing a failed import or a billing mismatch. It is not logged to an audit trail you can inspect. That is a genuine gap and it is listed as one in section 4.
Your mailbox, if you connect one, is read through a scoped OAuth connection you grant and can revoke from your own Google or Microsoft account at any time, without asking us. Annie never receives or stores your mail password. Message bodies are read in transit to write the one-line note on a contact and are not stored — the message table has no column to put a body in.
4. What Annie does not have
No SOC 2. No ISO 27001. No third-party penetration test. None of these has been carried out, and we make no claim to any of them. They are expensive and slow, and at Annie's current size the honest position is that the money has gone into the product instead. If your procurement process requires one of them, Annie will not pass it today, and we would rather you learn that here than three weeks into an evaluation.
No public status page. With a handful of customers, a status page would be a promise with nobody watching it. Instead: automated monitoring runs against the platform and alerts the founder directly, and if there is an outage or incident affecting your account you will be emailed at your account address. There is no uptime guarantee — that is stated plainly in the Terms and is not softened here.
No formal access-audit trail for founder-level database access, as described in section 3.
No bug bounty programme and no security.txt yet.
What is in place instead: row-level security on every table as described in section 1, secrets held server-side and never shipped in the browser bundle, captcha enforced across the whole authentication surface, billing and mailbox credentials held by the relevant provider rather than by Annie, automated dependency and platform-health checks, and an error log reviewed regularly.
5. Reporting a security problem
If you believe you have found a vulnerability in Annie, email mstubbs@meetannie.ai with the subject line SECURITY. It goes directly to the founder.
You will get a human acknowledgement within one working day, and an assessment of what we intend to do about it within five. We will tell you when it is fixed. We will not threaten you with legal action for reporting something in good faith, and we will credit you if you want to be credited.
If a personal data breach occurs that is likely to present a risk to people's rights, affected customers are notified and — where required — the UAE Data Office, without undue delay, as set out in section 10 of the Privacy Policy.
6. If Annie stops trading
The question every buyer with a legal team asks, and the one most vendors answer with silence. Annie is a young company run by one person. It could stop.
- You can take your records out at any time, without asking us. Settings → Download my data, and the same download on the screen shown when a trial ends with no card, builds one JSON file. It contains contacts, companies, jobs, candidates, deals, notes, meetings, tasks, pipeline links, placements, invoices and email history (the note, the subject, who it was with, the direction and the date). It lists uploaded files such as CVs and does not contain the files. It does not include Annie's generated market signals.
- That download still runs after billing stops. The records in the file stay readable without an active subscription, so losing access to Annie's features does not lock the download. The ownership-change log is the exception: that table still requires an active subscription to read, so it is absent from a download taken after billing has stopped.
- Notice. If Annie is discontinued, we will give at least 60 days' written notice to your account email before the service is switched off, and that same download will keep working for the whole of that period.
- The download is not held for payment. It runs from Settings, and from the trial-ended screen, without another charge. The ownership-change log above is the one record in the file that still requires an active subscription to read.
This commitment is mirrored as a clause in the Terms of Service so that it is contractual and not merely a page on a website.
7. Data processing agreement
Under the UAE PDPL, for the candidate and client-contact data you put into Annie, you are the controller and Annie is the processor: you decide why that data is held and we process it to provide the service on your instructions. For your own account data — your name, email, firm and billing details — Annie is the controller.
A signed data processing agreement is available on request from mstubbs@meetannie.ai, covering the processing scope described here, the subprocessor list in the Privacy Policy, breach notification, and deletion on termination. If your firm has its own DPA template, send it and we will review and sign it.
8. Contact
Security questions, DPA requests and procurement questionnaires all go to mstubbs@meetannie.ai. Annie is operated by Vantage Search Group ME DWC-LLC, registered in the Dubai South (DWC) free zone, licence number 14082.