Built for firm data, not just user data.
Your client list is the firm. We treat it that way: minimal collection, Canadian residency, and a page that tells you what we don't have before it tells you what we do.
Built in Canada, hosted in Canada.All firm data lives in the Canadian region — Supabase Postgres in ca-central-1, with row-level security isolating every firm. For practices where data residency is a client requirement, not a preference, that's a one-line answer most vendors can't give.
What we collect, and what we never see.
The shortest path to a trustworthy system is to not have the data in the first place. Ventura runs on metadata and the records your firm creates — nothing else.
- Mailbox metadataSender, recipient, timestamp — to keep last-touch honest. Rolling 13 weeks, then deleted.
- Calendar metadataAttendees, times, titles — to anchor the loop to the week you actually keep.
- Meeting recordings you bringProcessed for summary and candidates, at your instruction, per meeting.
- Records your firm createsTasks, pursuits, cadences, reviews — kept until your firm deletes them.
- Email bodiesNever written to our database. We read headers, not mail.
- Message attachmentsYour documents stay in your document system.
- Client financial dataNo GL, no bank feeds, no statements — until you connect an integration, explicitly.
- Anything for advertisingNo trackers, no pixels, no resale. There's no ad model here to feed.
Where your data goes when AI touches it.
Ventura uses Anthropic's Claude for meeting extraction and scoring. Here is the entire path, including the part that crosses the border — because you'd find it anyway, and you should hear it from us.
Meeting transcript or relationship signal, stored in ca-central-1.
Anthropic's API is US-hosted. The call crosses the border, is processed, and returns. Nothing is retained by Anthropic.
Candidates and scores land back in your firm's data, waiting for a human to commit.
No client data is used to train Anthropic's models. Our API agreement excludes training use, and no data leaves our infrastructure for any reason other than the call required to score it.
Anthropic does not retain the content of our API calls. The transcript goes out, the candidates come back, and the only copy lives in your firm's Canadian-region database.
The same principle as the roadmap: AI fills slots, it doesn't take seats. It drafts, suggests, and assembles. It never sends, commits, or decides. Every action in Ventura traces to a person.
The stack, in one place.
For the partner who reviews vendors, or the IT consultant they hire to. If you need more than this page, ask — we'll get on a call with whoever does your diligence.
Supabase Postgres with row-level security. Every query is scoped to your firm at the database layer, not the application layer.
ca-central-1TLS 1.2+ in transit, AES-256 at rest. Standard, and stated anyway.
In transit & at restGoogle and Microsoft single sign-on. No passwords stored by Ventura.
OAuth 2.0Read-only metadata scopes. Ventura cannot send mail, modify events, or read message bodies.
Read-onlyAnthropic Claude via API, US-processed, zero retention, excluded from training. Detailed above.
Anthropic APISupabase, Anthropic, Resend (transactional email). The complete list — there is no fourth.
3 totalRole-based access (partner / staff / admin permission levels) is in development and listed on the roadmap — not here, because this page only describes what ships today.
What we don't have yet.
We are not currently SOC 2 attested. We do not hold ISO 27001, HIPAA, or any certification issued by a third party. We are not going to claim otherwise, and we'd rather you hear it here than find it in a questionnaire.
SOC 2 Type I is planned as the firm count grows; the controls above are how we operate in the meantime. If your firm requires an attestation we don't have, tell us — it moves the date.
Questions a page can't answer?
Send your security questionnaire, or put your IT reviewer directly in touch. We answer the same week.