Adds a Security and Data docs section (below Triggers and webhooks) with two pages:
- Security (
/docs/security/overview) — posture, compliance and the Trust Center, org/project isolation, credential protection (AES-256-GCM at rest, TLS), token redaction, webhook signing, responsibilities, and vulnerability reporting.
- Data retention (
/docs/security/data-retention) — what Composio stores, 1-year retention, the per-project Log storage → "Don't store data" option (Composio keeps an audit record but does not store tool-call payloads), an honest "Where your data goes" section (data still flows to the destination provider and sub-processors during execution; links the Trust Center sub-processor list), and a contact-sales path for contractual arrangements. Includes a redacted dashboard screenshot.
Note: "Don't store data" controls what Composio retains; it is not framed as a zero-data-retention guarantee.
🤖 Generated with Claude Code