Careful with your data.
Honest about the limits.

Last updated 31 July 2026

A plain-language overview, maintained by Willow Intelligence, of how the product handles access and secrets today. It is not a security programme description, a certification, or an independent audit, and it doesn't claim to be one.

How it's built

What we can point to.

Encrypted in transit

This website, Willow Observatory, and the Willow gateway are served over HTTPS.

Authenticated access

Observatory features and Core API paths require an authenticated session or key. Unauthenticated calls to those paths are rejected rather than served.

Secrets stay server-side

Provider and service credentials are held server-side. They are not shipped in frontend code, and we will never ask you for a key by email.

Payment details

Card details are entered and handled by our payment processor rather than by Willow application code.

No perfect security

No system is perfectly secure, and we won't claim otherwise. This page describes how the product is built, not an audit or certification of it.

Security is shared. Willow looks after the service; you look after your own account credentials and the data you choose to bring in. We don't publish our internal infrastructure detail.

Using Willow well

Responsible use.

Willow is not a decision-maker

Willow helps AI keep the thread. It doesn't verify facts for you, and it isn't a substitute for medical, legal, or financial advice.

Don't paste secrets

Avoid putting passwords, keys, or payment details into any AI thread, Willow included.

Respect other people's data

Only bring in information you're allowed to process.

Tell us before you probe

Please report a suspected vulnerability rather than testing against production. We'd rather hear from you first.

Reporting

Found something? Tell us.

Email support@willow-intelligence.com with enough detail to reproduce the issue. A member of the Willow team will read it. Please give us a reasonable window to look into an issue before sharing it publicly, and don't access or modify data that isn't yours while testing.