Skip to content

Security at Midsummer.

The answers a security reviewer needs, in plain words. Questions not covered here go to hello@midsummerhq.com.

What Midsummer accesses

Midsummer connects to the customer's CRM and inbox, with scopes agreed in writing at onboarding. Access is read by default; anything beyond read is named explicitly before it is granted. Revoke access and the work stops.

What Midsummer can do without a person

Nothing outbound. Midsummer reads, ranks, drafts, and prepares. Every external message waits as a draft until a person on the customer's team approves it.

Approval and audit

Every action is logged with its source: what ran, what it said, and what came back. Approvals sit with the people named at onboarding, and any action can be opened and read afterwards.

Data handling

All connections are encrypted in transit over TLS. Data is stored with Midsummer's hosting provider in the United States. Customer data is kept for the duration of the engagement and deleted on request: hello@midsummerhq.com.

Model use

Reading and drafting are done by foundation models over API. Customer data is never sold. Midsummer is verifying each model provider's training terms in writing, and this page will be updated when that verification completes.

Subprocessors

Foundation-model API providers: Anthropic; Zhipu AI (GLM). Hosting: RackNerd. This list is updated before a new subprocessor is added.

Compliance

SOC 2 not started; security overview and DPA on request. Write to hello@midsummerhq.com.

Contact for security questions

hello@midsummerhq.com. A person answers.