↳ Security & Data
Your security review, answered in advance.
Where the documents live, who can reach them, what learns from them, and how they leave — answered as guarantees, before the checklist asks.
Residency and control
Where your documents live is your choice — set for your deployment and written into your agreement, with European infrastructure and zero data retention on the model accounts where you require it. They stay within that boundary for as long as they are with us. Where the data lives is the first question of every review; here the answer is the one you set.
Data at rest is encrypted. Storage and hosting follow the region set for your deployment and named in your DPA; answer generation and OCR run on Anthropic’s API, which offers no European processing region today, so those calls are covered by zero data retention rather than by a region.
Isolation between operations
Your operation's documents are completely isolated from every other operation's. That isolation is structural, not procedural — and it is verified continuously against the live system, not asserted once at audit time.
Enforced in the database by row-level security and re-proven by an automated cross-tenant test that runs in our CI on every relevant change.
No training, ever
Your documents never train anyone's systems — not ours, not any other party's, not in aggregate, not stripped of names. The knowledge your operation spent decades accumulating confers an advantage on no one but you.
Backed, where you require it, by a zero-retention agreement on our AI providers’ accounts, named in your DPA.
Authorized, expiring access
A document is opened only through access that is authorized and that expires. There is no standing way into your files waiting to be found; access exists for the moment it is needed and lapses on its own. What is not renewed is closed.
Files open only through authorized links that expire in sixty seconds; there is no standing cross-tenant path into them.
Complete erasure, including derivatives
Deleting a document removes it entirely, along with every derivative of it. Nothing remains to be retrieved, and nothing remains to answer from. When your retention obligation ends, so does our copy.
Deletion and full-workspace erasure are one authorized, irreversible operation; only the hosting provider’s backups age out on their own schedule, and are never used to restore erased data.
Sourced or silent
Every answer cites the exact document and page, and the cited passage opens for inspection. An answer that cannot be traced to your own record is not given; the gap is stated instead. For a document set that carries liability, that refusal is a security property, not a limitation.
Every answer also exports as a verifiable, audit-grade record — the cited passages, each source file’s content hash, and a hash of the record itself.
↳ Roadmap
What we are building toward.
We hold no certification today, and we show no badge we have not earned. The program is real and staged — here is what is already in place, and the order we build in.
Encryption in transit and at rest.
Database-enforced tenant isolation, re-proven in our CI on every change.
An append-only audit trail, and a no-content logging policy.
A no-training, zero-retention posture, named in your DPA.
Per-organization usage limits, so no single customer can affect the service of another.
SOC 2 Type I — our first formal milestone, as we exit pilot stage.
SOC 2 Type II — after the required observation window.
ISO 27001 — as the organization scales.
Bring the questionnaire.
Every item on your checklist should already be answered above. For anything that is not, put the question to us directly — we would rather face it before the contract than after.
Book a demo