Security

Last updated: October 8, 2026

This page describes how Barrow and Barrow for Word, our Microsoft Word add-in, are deployed and operated, for the people who review and administer software at our customers' firms. What we collect and how we use it is set out in our Privacy Policy.

Barrow for Word, for IT administrators

Barrow for Word is published by Barrow AI, Inc. in Microsoft Marketplace: https://marketplace.microsoft.com/en-us/product/office/WA200012258

  • What it is. An Office web add-in that runs in Word's task pane. Word loads it from https://word.barrow.site. No software is installed on the user's device.
  • Deployment. A Microsoft 365 administrator deploys it from the Microsoft 365 admin center (Settings, then Integrated apps) to everyone, to chosen users or to groups. Removing the assignment removes the add-in.
  • Permission. The add-in's manifest requests one permission, ReadWriteDocument: it can read and change the Word document that is open. The manifest is public: https://word.barrow.site/manifest.production.xml
  • Where it runs. Word on Windows, Word on Mac and Word on the web.
  • Account. Using it requires signing in to a Barrow account that belongs to a firm with access to Barrow for Word.

Network destinations

The add-in connects to these hosts, all over HTTPS:

  • word.barrow.site: the add-in's own pages
  • api.barrow.site: the Barrow service
  • barrow.us.auth0.com: sign in
  • appsforoffice.microsoft.com: Microsoft's Office library
  • us.i.posthog.com: usage diagnostics, described below
  • barrow.site: links to support, billing and these pages

When a user chooses to connect OneDrive or Google Drive, the add-in also opens that provider's own sign-in and file picker.

Signing in and access

  • Sign in. Sign in is handled by Auth0. A person signs in with an email address and password, or with Google. Barrow does not receive or store passwords.
  • Verified email. A new account must verify its email address before it can use Barrow.
  • One account, one identity. An account belongs to the sign-in that created it. Barrow does not join or move accounts because two sign-ins carry the same email address.
  • Access by firm. Every project, source document and report belongs to one firm and is available only to that firm's members. A person joins a firm through an invitation sent to their email address, which only a verified account with that address can accept. A firm's administrators can remove a member at any time.
  • Failed attempts. The service limits repeated failed sign-in tokens from one network address.

Your data

  • What the add-in sends. When a user asks the add-in to draft a section, answer a question about the sources, or check the writing, the relevant content of the open Word document is sent to the Barrow service so the request can be fulfilled. The add-in also reads the document's structure and content locally, to list its sections and to protect existing edits.
  • Source documents. Users add source documents by uploading them from their computer. Connecting OneDrive or Google Drive is optional: the user signs in to that provider and chooses the files, and Barrow's access is read only. The credentials that connection gives Barrow are stored encrypted.
  • Where it is stored. Files are stored in Amazon S3 in the United States (Ohio). The Barrow service and its database run in the United States (Virginia). The web application and the add-in's pages are served by Vercel.
  • In transit. Every connection to Barrow uses HTTPS with TLS 1.2 or later, and Barrow's hosts tell browsers to refuse unencrypted connections.
  • At rest. Files stored in Amazon S3 are encrypted at rest with AES-256.
  • AI processing. Project content is processed by AI model providers (Anthropic, Google and OpenAI) to produce the drafts, answers and checks a user requests. We do not use your project data to train AI models.
  • Ownership. Everything you upload and the reports you produce remain yours. We do not sell customer information.
  • Retention and deletion. See sections 10 and 11 of our Privacy Policy.

Usage diagnostics in the add-in

We use usage analytics, error diagnostics and masked recordings of the Barrow task pane for support and to improve reliability. Report text, source content and typed inputs are masked before a recording leaves the device. Recordings do not include Word's document canvas, source-file previews, console logs, authentication headers, or the contents of requests to the Barrow service.

Service providers

  • Sign in: Auth0
  • File storage: Amazon Web Services
  • Service and database hosting: Railway
  • Web and add-in hosting: Vercel
  • AI processing: Anthropic, Google, OpenAI
  • Payments: Stripe
  • Email: SendGrid
  • Usage analytics and masked recordings: PostHog
  • Error monitoring: Sentry

Security incidents

When we become aware of a security incident affecting customer information, we investigate it, contain it, and notify affected customers as required by law and by our agreements. See section 9 of our Privacy Policy.

Reporting a security concern

Email support@barrow.site with "Security report" in the subject line. Tell us what you found and how to reproduce it, and do not include passwords or access tokens. We will acknowledge your report and keep you informed while we look into it.