Security and architecture

Designed so that even we cannot read your data.

The database never stores personal data in readable form. Whatever sensitive material exists, exists encrypted under a key you keep outside the database. A database administrator, a backup, or an attacker with database access sees only ciphertext.

The data flow

What leaves, what stays, what is never written

What leaves for the AI

The text with the details that were detected replaced by placeholders: [NAME_1], [AFM_2], [IBAN_3]. The model answers over those. The real values are restored on your screen, inside the response stream. Detection accuracy is measured and published on the accuracy page.

What stays here, encrypted

On our own infrastructure at a European cloud provider, inside the EU. The mapping between placeholders and real values, under AES-256-GCM with a key from an environment variable (not in the database, not in the code). Vault search runs on HMAC fingerprints: your query never reaches SQL as plaintext.

What is never stored

Original files (held ephemerally, for minutes, in memory only), email threads (read live, written nowhere) and the unmasked text of your conversations.

The guarantees

One by one, with the mechanism next to each

Encryption wherever a value exists

An AES-256-GCM value vault, a separate and independent key for HMAC search, and the OAuth tokens of connected mailboxes encrypted too. Keys derive from a master key you control in the runtime environment.

Tamper-evident audit trail

Every audit row gets a sequence number and a keyed MAC over the previous one, forming a chain. Any later edit, delete or insertion breaks the chain from that point and is caught by verification. Without the key, not even a database administrator can rewrite history.

Fail-closed: when something breaks, we do not leak

If the detection service is unreachable, the request is not forwarded unmasked to the AI. It is refused. Availability is sacrificed before privacy, never the other way round.

Retention on a clock, and on your terms

Original files are deleted automatically within minutes and never touch the database. The encrypted vault mappings are purged automatically after 30 days. Conversation history (masked text only) stays until you delete it or close the account. For the strictest stance there is a session-only mode, where no value is ever written to a database, not even encrypted.

No hidden paths to third parties

Not even the fonts load from external CDNs. Every asset is served by us, so your browser talks to no third party. What travels to the AI provider (outside the EU) is the masked text, which is the very reason this product exists. Every such send is recorded with destination and time.

Your key, in your hands (optional)

With customer-held keys enabled, your data is encrypted under a key only your password can unlock. The database holds it wrapped, useless without you. While you are not signed in, not even we can read your data. That is not a promise, it is a technical impossibility.

A human has the last word

A privacy panel on every message (what was hidden, under which placeholder), an approve-before-burn preview on every document redaction, explicit warnings for unreadable handwriting and unsupported scripts. No silent sends.

To be precise

AI processing is performed by a provider outside the EU, over masked text. That is exactly the gap this product closes. The full sub-processor list and processing terms are public, and the measurements behind the detection claims have their own page.

Measured accuracy

Security questions before you start?

For a DPA, vendor questionnaires, or a technical call with your DPO, talk to us. Otherwise, try it free.

Try it free Contact us