Last verified July 29, 2026
Can I use Littlebird for confidential client work?
Yes, if your client agreements allow cloud tools. The app runs on your computer, and the memory it builds is encrypted and stored in the AWS cloud, with AES-256 at rest and in transit and TLS 1.3 on every connection. Littlebird is SOC 2 certified and never trains on or sells your data. If a contract requires strictly local-only processing, self-hosting is available at the Enterprise tier.
More detail
The honest starting point is the storage model: Littlebird is cloud based for individual users, so "is this acceptable for client work" depends on what your engagement letters and NDAs say about encrypted cloud tools. Many agreements permit them; some do not.
The controls map well to client work. Exclude the apps that should never be observed, pause collection during a sensitive session, and delete the last hour or day if something was captured that should not have been. GDPR and CCPA compliant data handling policies apply, and the audit picture (SOC 2 certification, recurring third-party testing) is documented at trust.littlebird.ai.
For organizations whose policies require data to stay inside their own infrastructure, Enterprise self-hosted deployments are the answer, with custom security and data controls and a custom contract.