Data and security
How we handle your records.
What we do with your data, stated plainly, and nothing we cannot back up.
- You send exports. Nothing is installed and nothing connects to your systems.
- Files arrive through a private upload link, never as email attachments.
- A person checks every file before anything is loaded.
- Processed on an encrypted workstation and by our AI provider, Anthropic (Claude), which does not train its models on our clients' data.
- Your data is loaded into its own separate store, apart from every other customer's.
- Deleted 30 days after the pack is delivered unless you convert to a subscription, or earlier on request, confirmed in writing.
What we accept, and what we do not
We accept quality records: CAPA, nonconformances, calibration, training, suppliers, documents, audit findings and the other registers in our templates. People appear only as names, employee IDs and roles.
We do not accept ITAR, EAR, CUI or other export-controlled technical data, or personal data beyond names, employee IDs and roles. The fit check asks about this before you pay. If you are unsure about a record, ask before uploading.
If restricted data arrives anyway, we stop, do not process it, delete it, and confirm the deletion to you in writing.
Where your data is processed
Your files are checked and processed on an encrypted workstation. The AI-assisted parts of the analysis are processed by Anthropic's Claude, as our named subprocessor, with model training on our clients' data turned off.
There is no customer login during the beta. You receive your pack as files at the review call.
Who sees it
The person who checks your data and reviews every page of your pack, and Anthropic as the processor for the analysis. We do not share it with anyone else. The Audit Defense Pack Services Agreement includes confidentiality terms, and your records remain yours.
How long we keep it
Your data is deleted 30 days after the pack is delivered, unless you convert to a subscription. You can ask us to delete it earlier at any time. Deletion covers your uploaded files, the store they were loaded into and the generated reports, and we confirm it in writing.
What we do not claim
We do not currently hold third-party security certifications or attestations such as SOC 2 or ISO 27001, and the beta is not approved for export-controlled data. If your supplier-security process needs something specific, tell us on the fit check and we will answer honestly.
This website
The answers you give on the fit check are sent to our own server so we can reply to you. See the privacy notice (draft).
Questions about data handling: email us.