Skip to content

Security foundation

Your customers' details stay private

Gran Minerva protects your customers' personal details. We swap names, emails, and other identifying details for codes (tokenization) before any analysis happens. If you prefer, you can do that swap yourself so real details never reach us at all.

Personal details replaced before analysis

We replace names, emails, and other personal details with codes before your data is analyzed or sent to AI.

Encrypted on Google Cloud

Your data is encrypted on Google Cloud and kept separate from every other company's data. Only the systems that need it can reach it.

Controlled access

Real details are only filled back in on our servers, and only when an approved screen needs to show them to you.

What happens to customer data

  • Personal details never go into our analysis tables or AI prompts.
  • Each code stays consistent, so we can still match records and spot patterns without seeing who anyone is.
  • Your stored data is encrypted with Google Cloud keys, and each company gets its own keys.
  • When you view your data, our servers swap the codes back to real details first. Raw codes never reach your browser.

Where we stand today

  • You can ask us to delete personal data. Some privacy-law workflows (GDPR/CCPA) are still being finished, and we track that work openly.
  • Found a security issue? Email security@granminerva.com.
  • We publish a list of the vendors that help us run the service and review it regularly.

Your Data, Your Control

Choose how your data is protected, or protect it yourself.

Platform Protection

  • Personal details are replaced with codes before any analysis or AI use
  • Each company's data is encrypted with its own Google Cloud keys
  • No personal details in our analysis tables, logs, or AI prompts

Bring Your Own Tokenization

Strictest option
  • Replace personal details with codes yourself before uploading
  • We never see real personal details, only your codes
  • The key that links codes to real people stays in your systems
  • Guide and code kit (SDK) for Python and Node.js planned
  • Your keys, your control, your rules

Both paths give you the same accurate early warnings. The only difference is who holds the keys.

BYOT is the strictest option: your customers' real details never leave your systems.

Your Data
You Swap In Codes
Upload Codes
We Analyze
You Swap Back
AES-256 encryption
No personal details in analysis

Contact names, emails, phone numbers, addresses, and account IDs. Anything that identifies a person. We only need the pattern, not the name.

Activity records (orders, visits, logins, service requests), money amounts (recurring revenue, contract value), satisfaction scores, dates, and company facts like industry, size, and region.

  1. Download our guide (or install the code kit)
  2. Swap personal details for codes in your own system before upload
  3. Turn on "I pre-tokenize my data" in Settings
  4. Upload as normal. Gran Minerva works with your codes.
  5. Swap the codes back on your end when you need real names

Works with Python 3.8+ and Node.js 18+. You keep the code-to-name key in your own secure storage, such as HashiCorp Vault, Google Secret Manager, AWS Secrets Manager, or Azure Key Vault. An open-source release is planned. Codes stay consistent, so your records still match up.

Read the BYOT SpecificationComing SoonDownload the SDKComing Soon

Security reviews

Doing a security review before you buy? We can share our vendor list, privacy policy, and review materials. We are always clear about what is built today versus what is still planned.

Responsible disclosure

Report possible security issues to security@granminerva.com. See security.txt for details.

Security | Gran Minerva | Gran Minerva