Security and architecture
Designed so that even we cannot read your data.
The database never stores personal data in readable form. Whatever sensitive material exists, exists encrypted under a key you keep outside the database. A database administrator, a backup, or an attacker with database access sees only ciphertext.
The data flow
What leaves, what stays, what is never written
What leaves for the AI
The text with the details that were detected replaced by placeholders: [NAME_1], [AFM_2], [IBAN_3]. The model answers over those. The real values are restored on your screen, inside the response stream. Detection accuracy is measured and published on the accuracy page.
What stays here, encrypted
On our own infrastructure at a European cloud provider, inside the EU. The mapping between placeholders and real values, under AES-256-GCM with a key from an environment variable (not in the database, not in the code). Vault search runs on HMAC fingerprints: your query never reaches SQL as plaintext.
What is never stored
Original files (held ephemerally, for minutes, in memory only), email threads (read live, written nowhere) and the unmasked text of your conversations.
The guarantees
One by one, with the mechanism next to each
Encryption wherever a value exists
An AES-256-GCM value vault, a separate and independent key for HMAC search, and the OAuth tokens of connected mailboxes encrypted too. Keys derive from a master key you control in the runtime environment.
Tamper-evident audit trail
Every audit row gets a sequence number and a keyed MAC over the previous one, forming a chain. Any later edit, delete or insertion breaks the chain from that point and is caught by verification. Without the key, not even a database administrator can rewrite history.
Fail-closed: when something breaks, we do not leak
If the detection service is unreachable, the request is not forwarded unmasked to the AI. It is refused. Availability is sacrificed before privacy, never the other way round.
Retention on a clock, and on your terms
Original files are deleted automatically within minutes and never touch the database. The encrypted vault mappings are purged automatically after 30 days. Conversation history (masked text only) stays until you delete it or close the account. For the strictest stance there is a session-only mode, where no value is ever written to a database, not even encrypted.
No hidden paths to third parties
Not even the fonts load from external CDNs. Every asset is served by us, so your browser talks to no third party. What travels to the AI provider (outside the EU) is the masked text, which is the very reason this product exists. Every such send is recorded with destination and time.
Your key, in your hands (optional)
With customer-held keys enabled, your data is encrypted under a key only your password can unlock. The database holds it wrapped, useless without you. While you are not signed in, not even we can read your data. That is not a promise, it is a technical impossibility.
A human has the last word
A privacy panel on every message (what was hidden, under which placeholder), an approve-before-burn preview on every document redaction, explicit warnings for unreadable handwriting and unsupported scripts. No silent sends.
To be precise
AI processing is performed by a provider outside the EU, over masked text. That is exactly the gap this product closes. The full sub-processor list and processing terms are public, and the measurements behind the detection claims have their own page.
Security questions before you start?
For a DPA, vendor questionnaires, or a technical call with your DPO, talk to us. Otherwise, try it free.