StaffboxTrust Center staffbox.ai Get updates Request documents

Security and data · checked 2 Oct 2026

What protects your data, and what doesn't yet.

Staffbox runs AI on a Mac in your building, so most of your data never reaches us. This page lists the main controls we rely on with their real status: running today, set at each install, planned, or not in place. We have no customers installed yet and no certifications. We would rather show you the gaps than hide them.

This page is for information. It is not a contract or a warranty and may change. A signed agreement governs. Staffbox is run by its founder, Hadi Irvani.

8in place
4on demo unit only
4partly in place
4set at each install
20planned
2not in place

System status

Overview

Two places hold data, and they are handled differently.

The unit in your buildingA Mac mini on your network. Models, memory and working copies of the files and mail it reads are stored on it. By design, cloud AI is off unless you ask in writing and use your own key (checked on our demo unit; in our draft pilot terms). We agree with your IT provider at install who patches and watches it.
Our own systemsThe staffbox.ai website, the lead form and our email. They hold what you send us before a pilot (name, contact, sample requests), not the data stored on your unit. Our practice is to see unit data only in a support session you have agreed.

Compliance

We are a new company and say so.

SOC 2Not started

No audit or readiness work yet. We aim to post the date here when we start.

Open-source agentIn place

The agent and its install script are public under the MIT licence: Staffbox-ai/staffbox. Per-site configuration is given to your IT provider at install.

InsuranceNone confirmed

No cyber or errors-and-omissions insurance confirmed.

Controls

"In place" means we checked it on 2 Oct 2026. "Demo unit" means checked on our own Mac mini on 1–2 Oct; on a customer unit the same item is set and recorded at install. "Set at install" means it is done per site and written in that site's install record; except where noted, it is not yet automatic in the installer.

You can check the website and email items yourself: curl -sI https://staffbox.ai, dig CAA staffbox.ai, dig TXT _dmarc.staffbox.ai, or SSL Labs.

In place checkedDemo unit checked on ours onlyPartial with exceptionsAt install per sitePlanned not yetNot in place

On the unit Mac mini, your network

AI models run locallyDemo unit

Open-weight models run through Ollama, which listens on the machine itself only (127.0.0.1), not the network.

No cloud AI fallbackDemo unit

The agent has no cloud provider configured. If the local model fails, the task fails; it does not quietly go to the cloud.

Firewall on, stealth mode onDemo unit

macOS firewall blocks inbound connections; the unit does not answer pings.

Remote access by SSH key onlyDemo unit

Password login is off. macOS records every SSH login in its system log. Sessions are agreed with your IT contact in advance.

Full-disk encryption (FileVault)At install

The installer stops if FileVault is off; our demo unit runs with the demo override (DEMO_UNIT=1), so its disk is not encrypted. On a customer unit it is checked with fdesetup status and written in the install record.

Draft-only email, no delete rightsAt install

Our aim is draft-only: sending and deleting turned off in the agent. Whether the mail platform can also block them at the permission level depends on the platform. Before install we tell your IT provider in writing which limits the platform enforces and which only the agent does.

Access limited to agreed folders and mailboxAt install

What it can read is agreed in writing before install. In a quote pilot: forwarded quote requests and one price-list file.

Patching by your IT providerAt install

Who applies macOS, Ollama, agent and model updates is agreed in writing at install. We re-run the test set before model updates. Your IT provider does not need to wait for us to apply a security patch.

Our infrastructure staffbox.ai, lead form, AWS

HTTPS only, TLS 1.2 or newerPartial

On staffbox.ai, this Trust Center, the status page and the pilot room, plain HTTP is redirected to HTTPS at the CDN (Amazon CloudFront, policy TLSv1.2_2021). The lead-form endpoint is an AWS API Gateway default address, whose minimum TLS version we have not tested.

Storage buckets privateIn place

All public access is blocked on the S3 buckets; the CDN reaches them through origin access control.

Encryption at rest in our AWS storageIn place

Website files, lead-form records, pilot-room records and CDN visit logs are encrypted at rest (AES-256, S3 server-side). The Gmail copy of each lead is held by Google under its own terms.

CDN visit logs deleted after 90 daysPartial

CDN logs for staffbox.ai (IP address, page, referrer) expire automatically. Logs kept by the lead-form and pilot-room functions have no expiry set yet. Website analytics is separate: see Website analytics.

Deploys without stored cloud keysIn place

GitHub Actions deploys through a short-lived AWS role (OIDC) that only the main branch can use. No AWS keys sit in the repository.

Browser security headersPartial

HSTS (one year), no MIME sniffing, same-origin framing only and a strict referrer policy on staffbox.ai, trust., status. and the pilot room. Not yet on the lead-form endpoint; no Content-Security-Policy yet.

Uptime monitoring, publicIn place

About every 5 minutes we check that the website, Trust Center, status page, lead-form gateway, pilot-room gate and email (MX) records respond. It does not test a form submission or mail delivery. Results: status.staffbox.ai.

Certificate issuance restricted (CAA)In place

DNS records limit which certificate authorities may issue certificates for staffbox.ai.

Automatic deletion of lead-form recordsPlanned

Each form entry is stored in our AWS account and a copy is emailed to the founder's inbox (Amazon SES to Gmail). Today both are deleted by hand; automatic expiry is planned.

Pilot-room recordsIn place

Comments and e-signatures in the private pilot room are kept in a private, encrypted, versioned bucket in our AWS account.

Organization people and accounts

People working on StaffboxFact

As of 2 Oct 2026 the founder is the only person working on Staffbox. Automated credentials also exist: the deploy role, the status monitor, the lead-form and pilot-room functions, and the demo worker (which reads lead-form entries). People invited to a pilot room can see only that room.

Separate cloud account for StaffboxPlanned

Staffbox shares an AWS account with the founder's other projects, and that account has other administrator users who could technically read Staffbox data. Moving Staffbox to its own account is planned.

Enforced review before releasePlanned

Some changes go through pull requests, but nothing yet enforces review or checks on the main branch. There is one developer, so no second reviewer.

Two-factor login required across the GitHub organizationPlanned

Not enforced at the organization level yet. The website repository sits on the founder's personal GitHub account, outside the organization.

Encrypted mail delivery policy (MTA-STS, TLS reporting)Partial

Published in testing mode: sending servers are asked to report TLS failures to us, but delivery is not blocked yet.

Outbound mail signed as staffbox.ai (DKIM)Planned

Signing keys are published; our mail is not yet sent through them.

Email domain protection (DMARC enforcement)Planned

SPF and DMARC records are published; DMARC is in monitoring mode, not yet set to reject. Enforcement follows outbound signing.

Written security policies and incident planPlanned

Access, incident response and vendor policies are not written yet.

For your IT provider

What an IT provider asks before a device goes on a client network. None of these is written down yet. We intend to publish each one here before the first install.

How remote access connectsPlanned

Whether our SSH session reaches the unit directly on your network, through a VPN, or through a tunnel, and which ports the unit listens on.

Agent update pathPlanned

Where agent updates come from, whether they are pulled or pushed, and how they are pinned or verified.

Mailbox permissionsPlanned

The mail platform supported and exactly what the worker may do: read, move, label, create drafts. Sending and deleting stay off.

Contracting entityPlanned

The legal name and jurisdiction of the party you sign with.

Outbound traffic allowlistPlanned

Every host and port a default unit connects to, so your firewall can deny everything else.

Incident notification timePlanned

How fast we tell your named contact about an incident touching a unit, our key, our update path or your data, and what we send.

Remote-access key custody and rotationPlanned

Where our SSH key is held, how often it rotates, and what happens to access if Staffbox stops operating.

Responsibility matrixPlanned

Who patches macOS, Ollama, the agent and models, and how fast for critical fixes.

Logs you can forwardPlanned

Which logs the unit keeps (remote logins, agent actions, mailbox access), for how long, and how to send them to your log system.

Backup and replacementPlanned

What is backed up, to a target you own, and how fast a failed unit is replaced.

Untrusted-email (prompt injection) test resultsPlanned

Inbound email is treated as untrusted. We will publish the test set and results for injection attempts against a default install.

Data handling

These are the terms we plan to put in our pilot agreement. They are not binding until you and Staffbox sign it, and the signed agreement controls over this page.

Your data is stored on siteDraft terms

Models, memory and working copies of the files and mail the worker reads are stored on the unit in your building. Our practice is to see them only if you send them to us during setup, or in a support session you have agreed.

No training on your dataDraft terms

Staffbox will not train or fine-tune a model on your data and will not give your data to anyone for model training. The providers listed under Subprocessors hold some data under their own terms. If you choose a cloud model, that provider's terms apply.

Cloud AI only in writing, on your keyDraft terms

If you want a cloud model, you ask in writing and supply your own key. Then that provider is yours, under your contract with them.

Memory you can readIn place

The worker's notes and memory are plain Markdown files you can open, edit or delete. The agent also keeps working files (logs, skills, caches) on the unit; the install record lists where.

Deletion within 14 days of exitDraft terms

The unit is returned or wiped in front of you. Within 14 days of exit we delete what we hold from your pilot and confirm in writing what was deleted and what remains (for example older versions or logs that expire on their own schedule).

Subprocessors

Companies that handle data for our own systems. By default nothing flows from the unit to them on its own; anything you send us during setup or support passes through Gmail and AWS.

CompanyWhat forDataRegion
Amazon Web ServicesWebsite hosting, lead form, pilot room, status monitor, alert email (SES, sent from alerts@hadimirvani.com)Lead-form entries, pilot-room comments and signatures, visit logsUS (Virginia)
CloudflareDNS and email forwarding for staffbox.aiEmail in transitGlobal
Google (Analytics)Website visit statistics. We ask first if the device time zone looks European; elsewhere it runs unless you decline or your browser sends Global Privacy ControlPage URL, referrer and traffic source, IP address (Google uses it for approximate location and says Analytics does not store it), page title, language, device, browser and screen size, a cookie ID, scrolls and outbound or file-download clicks, clicks on call/text/email links (with the link text), and that a form was started or sent (never what you typed).US
Microsoft (Clarity)Heatmaps and session replays of the website (recordings of a visit, tied to a cookie ID rather than your name), same consent rule as Google AnalyticsClicks, scrolls and mouse movement, page URL, IP address (for approximate location), device and browser, a cookie ID, and the page as you saw it; text typed into form fields is masked before it leaves your browser (Clarity "Balanced" masking, checked 2 Oct 2026); other on-page text, messages the site shows you and the page URL are notUS
LinkedIn (Insight Tag)Measuring LinkedIn ads and building ad audiences, same consent rulePage URL, referrer, IP address, browser, a cookie ID, and that a form was sent; LinkedIn matches this to your LinkedIn account if you are signed inUS
Google (Gmail)Our email inboxEmails you send us, and a copy of each lead-form entryUS
Google (Fonts)Typefaces on this siteIP address and browser details when a page loadsUS
GitHubSource code and deploysNo customer dataUS

Model weights are downloaded at install from the public Ollama library. We don't send your data to Ollama. macOS on the unit makes its normal Apple update connections. We aim to list any new subprocessor here, with the date, before it receives data.

Documents

Ask and we send them by email. Drafts are marked as drafts.

Unit security sheetRequest

One page: hardware, encryption, models, read and write rights, network, remote access, exit. Draft.

Pilot agreementRequest

Data, training, cloud and deletion terms. Draft, with counsel.

Install record templatePlanned

The checklist your IT provider signs at install: FileVault, access, permissions.

Deletion certificate samplePlanned

What you receive in writing when we delete our copies.

Security questionnaireSend yours

We answer your IT provider's questionnaire directly, gaps included.

FAQ

Does any of our data reach Staffbox?

Not automatically. We can see unit data only in a support session you have agreed. During setup you may send us sample requests and a price list so we can build your test set; we delete those files afterwards, and confirm in writing what was deleted and what remains. Leave out passwords and personal data.

Can Staffbox reach into our network?

Our practice is SSH with a named key, in sessions agreed with your IT contact. While our key is installed it can technically reach the unit; key custody rules are listed above as planned. Each login is logged by macOS. Your IT provider can remove our key whenever they choose.

What happens if the model gets something wrong?

By agreement the worker drafts and a person at your company approves anything that goes to a customer, supplier or regulator. Our aim is that it cannot send email or delete anything; before install we tell your IT provider in writing which limits the mail platform enforces and which only the agent does.

Why no SOC 2?

We are pre-revenue with no customers installed. A SOC 2 report tests a company's controls over months; we plan to start when we have customers to protect. Until then this page and our open code are what you can check.

How often is this page updated?

We aim to update it when a status changes and at least monthly. The date at the top is the last check; the change log below lists what moved.

Website analytics

staffbox.ai and this Trust Center use Google Analytics to count visits and see which pages are useful, Microsoft Clarity to record session replays and heatmaps (clicks, scrolls, mouse movement; text typed into form fields is masked), and the LinkedIn Insight Tag, which measures our LinkedIn ads, builds ad audiences and can link your visit to your LinkedIn account if you are signed in. They set cookies (for example _ga, _clck, li_fat_id). Google signals and ad-personalisation signals are off in Google Analytics, and it is not linked to Google Ads. All three follow the same consent rule below.

  • Who is asked: if your device's time zone is in Europe, is UTC or can't be read, nothing loads until you press Allow. Everyone else gets them unless you press Decline in Privacy choices. If your browser sends Global Privacy Control, none of them load unless you press Allow yourself.
  • Your choice is kept for a year in a sbx-consent cookie on staffbox.ai. Decline stops Google Analytics and Clarity on the page and deletes the cookies they set on staffbox.ai. LinkedIn can't be switched off mid-page: if it already loaded, it stops from your next page. Data already sent stays with them, and cookies LinkedIn and Microsoft keep on their own domains are theirs to manage.
  • Retention in Google Analytics: event-level data 2 months, user-level data 14 months (checked 2 Oct 2026). Aggregated reports are kept after that. Retention in Clarity and LinkedIn is set by Microsoft and LinkedIn; we have not checked their current periods.
  • Deletion: email hadi@staffbox.ai with the value of your _ga cookie and we will ask Google to delete that visitor's data. For Clarity and LinkedIn, email us and we will raise it with them.

Change log

DateChange
2 Oct 2026Trust Center and status page published. Security headers, CAA records, MTA-STS (testing) and TLS reporting turned on. Signing keys for outbound mail published. Claims checked against our live setup and corrected where they overstated (review before release, who has access, lead-form copies, partial controls).

Report a security issue

Email hadi@staffbox.ai with "Security issue" in the subject. We aim to reply within one business day. In scope: staffbox.ai, trust.staffbox.ai, status.staffbox.ai and the pilot room. If you act in good faith, stay within that scope, avoid other people's data and service disruption, and report promptly, we will not take legal action against you for research on our own systems. We can't speak for third-party providers. There is no bug bounty. Please don't test against a customer's unit. Machine-readable contact: security.txt.