Sensitive by nature. Private by design.

People bring Pip their hardest conversations: performance, medical leave, investigations, terminations. Here is exactly how that information is kept safe and secure.

One workspace per company

Every record — conversations, activity, integration settings, policy sources — carries the company it belongs to. The database checks that stamp on every single read and write, so one customer physically cannot load another customer's data, even if something in the app went wrong.

Conversations stay with the person who had them

HR questions often name real people. Your chats are readable only by you. Company admins can see the activity record of consequential actions — who asked for what and what was approved — but not the private conversation text of other users.

Nothing consequential happens without approval

Pip advises and recommends. Hires, terminations, pay changes, document sends and licence purchases are queued as recommendations and only run after a named human approves them. Every approval is written to the activity record.

Credentials are never stored in the browser

Connections to your HRIS and SaaS tools are held by our integration provider and referenced by encrypted keys held server-side. Keys are never sent to the browser and never appear in chat.

A retention window you choose

Your admin sets how long conversations and activity are kept — 12 months by default. Anything older is deleted automatically.

Your data, on request

You can delete your own conversation history at any time from your workspace settings, and admins can shorten the retention window for the whole company. Deletions are immediate and permanent.

Open workspace settings

Your company's audit trail

Every advisory answer and every action generates a protected record: initiating user, timestamp, request, recommendation, approval, integration used, previous and new values, and result.

Loading audit events...