Security and data · checked 2 Oct 2026
What protects your data, and what doesn't yet.
Staffbox runs AI on a Mac in your building, so most of your data never reaches us. This page lists the main controls we rely on with their real status: running today, set at each install, planned, or not in place. We have no customers installed yet and no certifications. We would rather show you the gaps than hide them.
This page is for information. It is not a contract or a warranty and may change. A signed agreement governs. Staffbox is run by its founder, Hadi Irvani.
Overview
Two places hold data, and they are handled differently.
Compliance
We are a new company and say so.
No audit or readiness work yet. We aim to post the date here when we start.
The agent and its install script are public under the MIT licence: Staffbox-ai/staffbox. Per-site configuration is given to your IT provider at install.
No cyber or errors-and-omissions insurance confirmed.
Controls
"In place" means we checked it on 2 Oct 2026. "Demo unit" means checked on our own Mac mini on 1–2 Oct; on a customer unit the same item is set and recorded at install. "Set at install" means it is done per site and written in that site's install record; except where noted, it is not yet automatic in the installer.
You can check the website and email items yourself: curl -sI https://staffbox.ai, dig CAA staffbox.ai, dig TXT _dmarc.staffbox.ai, or SSL Labs.
On the unit Mac mini, your network
Open-weight models run through Ollama, which listens on the machine itself only (127.0.0.1), not the network.
The agent has no cloud provider configured. If the local model fails, the task fails; it does not quietly go to the cloud.
macOS firewall blocks inbound connections; the unit does not answer pings.
Password login is off. macOS records every SSH login in its system log. Sessions are agreed with your IT contact in advance.
The installer stops if FileVault is off; our demo unit runs with the demo override (DEMO_UNIT=1), so its disk is not encrypted. On a customer unit it is checked with fdesetup status and written in the install record.
Our aim is draft-only: sending and deleting turned off in the agent. Whether the mail platform can also block them at the permission level depends on the platform. Before install we tell your IT provider in writing which limits the platform enforces and which only the agent does.
What it can read is agreed in writing before install. In a quote pilot: forwarded quote requests and one price-list file.
Who applies macOS, Ollama, agent and model updates is agreed in writing at install. We re-run the test set before model updates. Your IT provider does not need to wait for us to apply a security patch.
Our infrastructure staffbox.ai, lead form, AWS
On staffbox.ai, this Trust Center, the status page and the pilot room, plain HTTP is redirected to HTTPS at the CDN (Amazon CloudFront, policy TLSv1.2_2021). The lead-form endpoint is an AWS API Gateway default address, whose minimum TLS version we have not tested.
All public access is blocked on the S3 buckets; the CDN reaches them through origin access control.
Website files, lead-form records, pilot-room records and CDN visit logs are encrypted at rest (AES-256, S3 server-side). The Gmail copy of each lead is held by Google under its own terms.
CDN logs for staffbox.ai (IP address, page, referrer) expire automatically. Logs kept by the lead-form and pilot-room functions have no expiry set yet. Website analytics is separate: see Website analytics.
GitHub Actions deploys through a short-lived AWS role (OIDC) that only the main branch can use. No AWS keys sit in the repository.
HSTS (one year), no MIME sniffing, same-origin framing only and a strict referrer policy on staffbox.ai, trust., status. and the pilot room. Not yet on the lead-form endpoint; no Content-Security-Policy yet.
About every 5 minutes we check that the website, Trust Center, status page, lead-form gateway, pilot-room gate and email (MX) records respond. It does not test a form submission or mail delivery. Results: status.staffbox.ai.
DNS records limit which certificate authorities may issue certificates for staffbox.ai.
Each form entry is stored in our AWS account and a copy is emailed to the founder's inbox (Amazon SES to Gmail). Today both are deleted by hand; automatic expiry is planned.
Comments and e-signatures in the private pilot room are kept in a private, encrypted, versioned bucket in our AWS account.
Organization people and accounts
As of 2 Oct 2026 the founder is the only person working on Staffbox. Automated credentials also exist: the deploy role, the status monitor, the lead-form and pilot-room functions, and the demo worker (which reads lead-form entries). People invited to a pilot room can see only that room.
Staffbox shares an AWS account with the founder's other projects, and that account has other administrator users who could technically read Staffbox data. Moving Staffbox to its own account is planned.
Some changes go through pull requests, but nothing yet enforces review or checks on the main branch. There is one developer, so no second reviewer.
Not enforced at the organization level yet. The website repository sits on the founder's personal GitHub account, outside the organization.
Published in testing mode: sending servers are asked to report TLS failures to us, but delivery is not blocked yet.
Signing keys are published; our mail is not yet sent through them.
SPF and DMARC records are published; DMARC is in monitoring mode, not yet set to reject. Enforcement follows outbound signing.
Access, incident response and vendor policies are not written yet.
For your IT provider
What an IT provider asks before a device goes on a client network. None of these is written down yet. We intend to publish each one here before the first install.
Whether our SSH session reaches the unit directly on your network, through a VPN, or through a tunnel, and which ports the unit listens on.
Where agent updates come from, whether they are pulled or pushed, and how they are pinned or verified.
The mail platform supported and exactly what the worker may do: read, move, label, create drafts. Sending and deleting stay off.
The legal name and jurisdiction of the party you sign with.
Every host and port a default unit connects to, so your firewall can deny everything else.
How fast we tell your named contact about an incident touching a unit, our key, our update path or your data, and what we send.
Where our SSH key is held, how often it rotates, and what happens to access if Staffbox stops operating.
Who patches macOS, Ollama, the agent and models, and how fast for critical fixes.
Which logs the unit keeps (remote logins, agent actions, mailbox access), for how long, and how to send them to your log system.
What is backed up, to a target you own, and how fast a failed unit is replaced.
Inbound email is treated as untrusted. We will publish the test set and results for injection attempts against a default install.
Data handling
These are the terms we plan to put in our pilot agreement. They are not binding until you and Staffbox sign it, and the signed agreement controls over this page.
Models, memory and working copies of the files and mail the worker reads are stored on the unit in your building. Our practice is to see them only if you send them to us during setup, or in a support session you have agreed.
Staffbox will not train or fine-tune a model on your data and will not give your data to anyone for model training. The providers listed under Subprocessors hold some data under their own terms. If you choose a cloud model, that provider's terms apply.
If you want a cloud model, you ask in writing and supply your own key. Then that provider is yours, under your contract with them.
The worker's notes and memory are plain Markdown files you can open, edit or delete. The agent also keeps working files (logs, skills, caches) on the unit; the install record lists where.
The unit is returned or wiped in front of you. Within 14 days of exit we delete what we hold from your pilot and confirm in writing what was deleted and what remains (for example older versions or logs that expire on their own schedule).
Subprocessors
Companies that handle data for our own systems. By default nothing flows from the unit to them on its own; anything you send us during setup or support passes through Gmail and AWS.
| Company | What for | Data | Region |
|---|---|---|---|
| Amazon Web Services | Website hosting, lead form, pilot room, status monitor, alert email (SES, sent from alerts@hadimirvani.com) | Lead-form entries, pilot-room comments and signatures, visit logs | US (Virginia) |
| Cloudflare | DNS and email forwarding for staffbox.ai | Email in transit | Global |
| Google (Analytics) | Website visit statistics. We ask first if the device time zone looks European; elsewhere it runs unless you decline or your browser sends Global Privacy Control | Page URL, referrer and traffic source, IP address (Google uses it for approximate location and says Analytics does not store it), page title, language, device, browser and screen size, a cookie ID, scrolls and outbound or file-download clicks, clicks on call/text/email links (with the link text), and that a form was started or sent (never what you typed). | US |
| Microsoft (Clarity) | Heatmaps and session replays of the website (recordings of a visit, tied to a cookie ID rather than your name), same consent rule as Google Analytics | Clicks, scrolls and mouse movement, page URL, IP address (for approximate location), device and browser, a cookie ID, and the page as you saw it; text typed into form fields is masked before it leaves your browser (Clarity "Balanced" masking, checked 2 Oct 2026); other on-page text, messages the site shows you and the page URL are not | US |
| LinkedIn (Insight Tag) | Measuring LinkedIn ads and building ad audiences, same consent rule | Page URL, referrer, IP address, browser, a cookie ID, and that a form was sent; LinkedIn matches this to your LinkedIn account if you are signed in | US |
| Google (Gmail) | Our email inbox | Emails you send us, and a copy of each lead-form entry | US |
| Google (Fonts) | Typefaces on this site | IP address and browser details when a page loads | US |
| GitHub | Source code and deploys | No customer data | US |
Model weights are downloaded at install from the public Ollama library. We don't send your data to Ollama. macOS on the unit makes its normal Apple update connections. We aim to list any new subprocessor here, with the date, before it receives data.
Documents
Ask and we send them by email. Drafts are marked as drafts.
One page: hardware, encryption, models, read and write rights, network, remote access, exit. Draft.
Data, training, cloud and deletion terms. Draft, with counsel.
The checklist your IT provider signs at install: FileVault, access, permissions.
What you receive in writing when we delete our copies.
We answer your IT provider's questionnaire directly, gaps included.
FAQ
Does any of our data reach Staffbox?
Not automatically. We can see unit data only in a support session you have agreed. During setup you may send us sample requests and a price list so we can build your test set; we delete those files afterwards, and confirm in writing what was deleted and what remains. Leave out passwords and personal data.
Can Staffbox reach into our network?
Our practice is SSH with a named key, in sessions agreed with your IT contact. While our key is installed it can technically reach the unit; key custody rules are listed above as planned. Each login is logged by macOS. Your IT provider can remove our key whenever they choose.
What happens if the model gets something wrong?
By agreement the worker drafts and a person at your company approves anything that goes to a customer, supplier or regulator. Our aim is that it cannot send email or delete anything; before install we tell your IT provider in writing which limits the mail platform enforces and which only the agent does.
Why no SOC 2?
We are pre-revenue with no customers installed. A SOC 2 report tests a company's controls over months; we plan to start when we have customers to protect. Until then this page and our open code are what you can check.
How often is this page updated?
We aim to update it when a status changes and at least monthly. The date at the top is the last check; the change log below lists what moved.
Website analytics
staffbox.ai and this Trust Center use Google Analytics to count visits and see which pages are useful, Microsoft Clarity to record session replays and heatmaps (clicks, scrolls, mouse movement; text typed into form fields is masked), and the LinkedIn Insight Tag, which measures our LinkedIn ads, builds ad audiences and can link your visit to your LinkedIn account if you are signed in. They set cookies (for example _ga, _clck, li_fat_id). Google signals and ad-personalisation signals are off in Google Analytics, and it is not linked to Google Ads. All three follow the same consent rule below.
- Who is asked: if your device's time zone is in Europe, is UTC or can't be read, nothing loads until you press Allow. Everyone else gets them unless you press Decline in Privacy choices. If your browser sends Global Privacy Control, none of them load unless you press Allow yourself.
- Your choice is kept for a year in a
sbx-consentcookie on staffbox.ai. Decline stops Google Analytics and Clarity on the page and deletes the cookies they set on staffbox.ai. LinkedIn can't be switched off mid-page: if it already loaded, it stops from your next page. Data already sent stays with them, and cookies LinkedIn and Microsoft keep on their own domains are theirs to manage. - Retention in Google Analytics: event-level data 2 months, user-level data 14 months (checked 2 Oct 2026). Aggregated reports are kept after that. Retention in Clarity and LinkedIn is set by Microsoft and LinkedIn; we have not checked their current periods.
- Deletion: email hadi@staffbox.ai with the value of your
_gacookie and we will ask Google to delete that visitor's data. For Clarity and LinkedIn, email us and we will raise it with them.
Change log
| Date | Change |
|---|---|
| 2 Oct 2026 | Trust Center and status page published. Security headers, CAA records, MTA-STS (testing) and TLS reporting turned on. Signing keys for outbound mail published. Claims checked against our live setup and corrected where they overstated (review before release, who has access, lead-form copies, partial controls). |
Report a security issue
Email hadi@staffbox.ai with "Security issue" in the subject. We aim to reply within one business day. In scope: staffbox.ai, trust.staffbox.ai, status.staffbox.ai and the pilot room. If you act in good faith, stay within that scope, avoid other people's data and service disruption, and report promptly, we will not take legal action against you for research on our own systems. We can't speak for third-party providers. There is no bug bounty. Please don't test against a customer's unit. Machine-readable contact: security.txt.