Lack of formal security certifications (SOC 2 Type II, ISO 27001) limits enterprise suitability for regulated industries. Cloud version subject to US CLOUD Act despite EU hosting. Full agentic access to email, CRM, databases, and APIs. As a relatively young startup, security audit trail is limited.
Consider self-hosted deployment (open-source MIT license) for complete data control and elimination of sovereignty/training concerns. Cloud version in Germany offers EU data residency advantage. Not suitable for HIPAA or regulated industries requiring SOC 2. Excellent option for privacy-conscious teams willing to self-host. Monitor for SOC 2 certification progress.