Autonomous,
on the record.
Closos only does what your policy permits — and proves it for every action. So legal smiles, execs sleep, and you keep selling.
Row-level isolation
Every table enforces RLS scoped by org and workspace. A leak inside Closos would have to break Postgres itself — your data never sits next to anyone else's.
Trust Receipts, on every action
Every move signs its name: the evidence used, the policy matched, the approver who cleared it, what it would take to roll back. Downloadable as a signed PDF.
Policy guardrails that hold
Approval chains, brand voice, spend limits, role boundaries. Two of them can't be unlocked — not in a sprint, not for a VIP, not by your admin. By design.
DSR queue, on the clock
A built-in data-subject-request queue with SLA tracking, signed export bundles, and one-click erasure. GDPR and CCPA aligned without a project plan.
Secrets & SSO
Every third-party token encrypted at rest. SAML SSO and SCIM on Enterprise. Service-role keys never touch a browser, ever.
No fine print. No "best effort."
- Encryption in transit
- TLS 1.2+ on every request, no exceptions.
- Encryption at rest
- AES-256, managed by our cloud provider.
- Data residency
- Currently US-only. EU residency is on the roadmap — ask us where it sits.
- Email body storage
- Metadata only. The body stays in your inbox.
- Audit retention
- Configurable, 30 to 365 days on Team.
- Sub-processors
- Listed on request. Email hello@closos.com and we send the same day.
SOC 2 is on the roadmap; we are not yet certified. Need a DPA, a current security questionnaire, or subprocessor list? security@closos.com. We answer the same day.
Operated by EthicalBrain Technologies · Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates.
Two rules Closos can't unlock.
Not for anyone.
Irreversible actions need human approval. Trust Receipts are immutable once signed. Your admin can't disable either. Neither can ours. That's the floor — everything else is your policy.
See a sample receipt
