Careful with your data.
Honest about the limits.
Last updated 31 July 2026
A plain-language overview, maintained by Willow Intelligence, of how the product handles access and secrets today. It is not a security programme description, a certification, or an independent audit, and it doesn't claim to be one.
What we can point to.
Encrypted in transit
This website, Willow Observatory, and the Willow gateway are served over HTTPS.
Authenticated access
Observatory features and Core API paths require an authenticated session or key. Unauthenticated calls to those paths are rejected rather than served.
Secrets stay server-side
Provider and service credentials are held server-side. They are not shipped in frontend code, and we will never ask you for a key by email.
Payment details
Card details are entered and handled by our payment processor rather than by Willow application code.
No perfect security
No system is perfectly secure, and we won't claim otherwise. This page describes how the product is built, not an audit or certification of it.
Security is shared. Willow looks after the service; you look after your own account credentials and the data you choose to bring in. We don't publish our internal infrastructure detail.
Responsible use.
Willow is not a decision-maker
Willow helps AI keep the thread. It doesn't verify facts for you, and it isn't a substitute for medical, legal, or financial advice.
Don't paste secrets
Avoid putting passwords, keys, or payment details into any AI thread, Willow included.
Respect other people's data
Only bring in information you're allowed to process.
Tell us before you probe
Please report a suspected vulnerability rather than testing against production. We'd rather hear from you first.
Found something? Tell us.
Email support@willow-intelligence.com with enough detail to reproduce the issue. A member of the Willow team will read it. Please give us a reasonable window to look into an issue before sharing it publicly, and don't access or modify data that isn't yours while testing.