Bank-grade encryption, role-based access, audit logs, and a strict no-training AI pledge — built for confidential business documents.
All upload, download, and API traffic is HTTPS-only with TLS 1.2+. HSTS is enabled site-wide.
Documents are stored in Cloudflare R2 with AES-256 encryption at rest. Database is Postgres on Railway (EU West) with encrypted volumes.
Role-based access (owner, admin, member) on every team. Server actions verify session + team membership before reading any document.
Every document upload, review run, role change, and deletion is recorded with actor, IP, user agent, and timestamp. Retained for the life of the account.
Documents are retained for as long as your team needs them. Soft-delete in the dashboard hides them; hard-delete on request purges from R2 + DB within 30 days.
We never use your contracts to train models. Inference requests carry team and user metadata for traceability only, and the model provider is contractually barred from training on them. Your contracts are your contracts.
A small list of best-in-class providers we use to deliver the service. All third-party sub-processors maintain SOC 2 Type II or ISO 27001 certifications.
All accounts get encrypted processing and zero data retention for training. Scale and Pro tiers include signed DPA and SOC 2 questionnaire assistance.