Security
Last updated: July 28, 2026
Security questions about Grove can be sent to info@hamelintech.com. To report a vulnerability, see Responsible Disclosure below.
Infrastructure
Grove runs on Google Cloud Platform. Customer Content is stored in Firebase, using Cloud Firestore for structured data and Firebase Storage for files, and accounts are managed by Firebase Authentication. The web application is served through Vercel. We do not run our own servers or data centers.
Encryption
Customer Content is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256, which Google Cloud applies to Firestore and Firebase Storage by default.
Access Control
Knowledge collections are private by default. Each collection is readable only by the members its owner adds, and access can be revoked at any time. These controls are enforced on the server by database security rules, not only in the interface.
Authentication
Accounts are authenticated through Firebase Authentication, using email and password or Google sign-in. Passwords are handled by Firebase and are never stored on Grove's own systems. Credentials for third-party integrations you connect are held in a secured vault on the AI provider's side and injected only at run time; Grove never stores those tokens.
AI Processing and Subprocessors
Digital employee tasks are processed using AI models operated by Anthropic. Relevant portions of Customer Content are transmitted to Anthropic only to perform the tasks you request, and Grove does not permit Anthropic to use Customer Content to train models for other customers. A full list of subprocessors, including our AI and infrastructure providers, is on our Subprocessors page.
Data Isolation
Grove is a multi-tenant service. Each company's data is separated logically by per-tenant identifiers and kept isolated by our database security rules, which restrict every read and write to the account and company the data belongs to.
Monitoring and Incident Response
We monitor the Service for security events. If we become aware of a security incident involving your Customer Content, we will notify affected customers without undue delay. This commitment is also reflected in our Privacy Policy and Terms of Service.
Compliance
Grove is not currently SOC 2 certified. Enterprise customers can request a security review and a custom Data Processing Addendum as part of onboarding.
Responsible Disclosure
If you believe you've found a security vulnerability in Grove, please report it to info@hamelintech.com. Include enough detail to reproduce the issue. We ask that you give us a reasonable opportunity to address it before public disclosure, and we will not pursue legal action against good-faith security research conducted under this policy.