ExcelsiusBuilt to compound.
The systemWhat it doesSee a sample weekProofPricingStart free

Security

The OAuth token vault

When you connect an account, we store its OAuth token encrypted at rest using AES-256-GCM (industry-standard authenticated encryption). The encryption key is held server-side and rotated periodically. Tokens are decrypted only inside a managed run — to do that week's work while your subscription is active — and are never logged. When you disconnect a service or cancel, the stored token is cleared.

What each connection can do

Every connection is scoped to the narrowest access its job needs, and each is revocable from that provider's own settings at any time:

  • Notion — read and write the operating-system workspace we install for you. This is where your data and structure live.
  • Google Calendar — read your events to avoid conflicts, and create solo time-blocks (focus / prep) that you can undo. It never edits, moves, or deletes your real meetings, and never invites anyone.
  • Gmail — draft-only. It creates drafts and never sends; drafts sit in your Gmail for you to review and send yourself. To draft a contextual reply it reads only that one thread — never the broader inbox and never your contacts.
  • Stripe — read-only. It reads your revenue and subscription figures to report on them. It cannot create charges, issue refunds, or move money.

What runs on our infrastructure vs. yours

  • Our infrastructure: the app (Next.js on Vercel); the customer + session database (Supabase Postgres with row-level security); and the managed agent runtime that does your weekly work — it runs on Excelsius's infrastructure and calls Anthropic's API on Excelsius's account. You do not run the agents and you do not need your own Anthropic account.
  • Your accounts: your Notion workspace and the data inside it; and the Google (Calendar + Gmail) and Stripe accounts you connect with your permission. These stay yours; revoke access from each provider anytime.

Payment security

There are two separate Stripe relationships, and they don't mix. First, Stripe processes your Excelsius subscription payment under their PCI Service Provider Level 1 compliance — we never see, touch, or store your card information; we hold only a Stripe customer ID and which plan you're on. Second, and only if you choose to connect it, Excelsius reads your own Stripe account read-only, to report on your revenue — it never moves money.

Disclosure

If you discover a security issue with Excelsius, please report it to support@excelsius.co with the subject “Security:” followed by a short description. We'll acknowledge within 1 business day and coordinate disclosure with you.

Subprocessors

We use the following subprocessors to operate Excelsius. Each has been chosen for security posture and is bound by their own data-handling commitments.

  • Vercel — hosting + edge delivery
  • Supabase — Postgres database (customers, sessions, run records, audit log)
  • Stripe — payment processing for your subscription
  • Anthropic — Claude API (the Setup Specialist, the weekly managed automation, and agent work)
  • Google — Calendar + Gmail access, when you connect them

Contact

Security questions or reports: support@excelsius.co