Security

Last updated: July 28, 2026

inDemo logs into your product and drives it in front of your prospects. That is a lot of trust to ask for, so this page describes what actually happens to your credentials, your product, and your leads' data — in the specific rather than the reassuring.

The demo runs inside a fence

Every demo session runs in a headless browser governed by a navigation policy. Before the agent performs any action — a click, a form fill, a navigation — the action passes through a single gate that checks it against an allow-list of origins derived from your app URL and login URL, plus a list of forbidden paths.

This is why the agent cannot wander onto your admin panel, a third-party site, or anything else you didn't point it at — the restriction is structural, not a prompt instruction the model might ignore.

Credentials you connect

To demo your product, you give inDemo a demo account. That credential is treated as a reversible secret:

We strongly recommend connecting a dedicated demo account with demo data, not a real production login. Nothing about the design requires production access.

Demo recordings

Every demo is recorded and transcribed so you can audit what was said. Those recordings are the most sensitive thing we store, and they're handled accordingly:

Your account

Where your data lives

The application and its Postgres database run on Fly.io with Frankfurt as the primary region. Recordings live in private S3-compatible object storage. Transport is TLS end to end.

Language-model inference is not in the EU: narration and answers are generated by OpenAI and Google models hosted in the United States. If EU-only processing is a hard requirement for you, tell us before you sign up rather than after — we would rather lose the deal than misrepresent this.

Subprocessors

These are the third parties that may process data on our behalf:

ProviderWhat it doesWhere
Fly.ioApplication hosting and computeFrankfurt (primary), EU
TigrisObject storage for demo recordingsEU / global edge
OpenAILanguage model for demo narration and answersUS
GoogleGemini Live for real-time voiceUS
ResendTransactional and follow-up emailUS / EU
PolarSubscription billing and paymentsEU
CloudflareTurnstile bot protection, CDN for this siteGlobal edge
FirecrawlReading the public docs you point us atUS
PostHogWebsite analytics for indemo.aiFrankfurt, EU

We'll post changes to this list here. See the Data Processing Addendum for the contractual version.

What we don't have yet

inDemo is an early-stage product and we'd rather you learn this here than in a questionnaire three weeks into an evaluation. As of today we do not have:

SOC 2 or ISO 27001 certification · a third-party penetration test · SAML/OIDC single sign-on · multi-factor authentication · a contractual uptime SLA.

If any of those is a blocker for you, email us and say which one. It tells us what to build next, and we'll tell you honestly where it sits.

Reporting a vulnerability

Found something? Email support@indemo.ai with "Security" in the subject line. We'll acknowledge within two business days. We won't pursue legal action against anyone who reports a genuine issue in good faith and gives us a reasonable window to fix it before disclosing.

Questions

Security review, questionnaire, or something this page doesn't answer — support@indemo.ai. A real person answers.

Get started

Never miss another lead.

30 free demo minutes · no card