Security

Your customers' drawings are under NDA. We build like it.

The safeguards below aren't features on a pricing tier. They're the rules the product is built on, and none of them can be switched off.

A person approves every action

Reading a document produces data for review, nothing more. Quotes, acknowledgments and reports are generated only after someone approves, and nothing is emailed, written or released on the software's say-so.

Your originals are never changed

Documents are stored exactly as received. Extracted values are kept separately and point back to the page and region they came from, so any field can be traced to its source in one click.

An audit trail from the first day

Who viewed a document, who changed a value, who approved it and when. The log is append-only: the application can add to it but cannot edit or delete it.

Customer isolation in the database

Every customer's records are separated by row-level security in the database itself. Isolation doesn't depend on every query in the application remembering to filter correctly.

Read-only to your systems

When we connect to your ERP or file shares, we use a dedicated account with select-only permissions. We never write back to your ERP.

No inbound ports, no VPN

Connectors run inside your network and only make outbound HTTPS calls. There's nothing to open on your firewall and nothing to ask of your IT provider.

Untrusted input

A document can't tell the software what to do.

RFQs, supplier emails and scanned PDFs come from outside your company, and any of them can contain text written to look like instructions. We treat every document as untrusted.

That's why the approval rule matters so much: whatever the AI reads, the only thing it can produce is a set of values waiting for review. It has no way to send an email, change a record or release a package. A person does that, after looking.

Where it runs

Deployment is a setting, not a rebuild.

The platform is built only on portable pieces (containers, Postgres and S3-compatible storage), and every AI call goes through a single integration point. Which model runs, and where, is configured per customer.

Commercial cloudHosted by us. Document reading uses a commercial AI provider through a single, audited integration.Standard
DedicatedYour own isolated environment and model configuration.By arrangement
Sovereign cloudDeployed in a government cloud region such as AWS GovCloud.By arrangement
Self-hostedRuns on your infrastructure with open-weight models, fully inside your network.By arrangement

Sign-in

Authentication is handled by a dedicated identity provider. We don't build our own login system and we never store your passwords. Each person has a role (reviewer, approver or admin) that controls what they can do.

Certifications, honestly

We don't hold SOC 2, CMMC or ITAR-related certifications today, and we won't imply otherwise. If your contracts flow down specific requirements, tell us on a call and we'll walk through which deployment option fits and what it would take.

Have a security questionnaire?

Send it over with your demo request. We'd rather answer the hard questions early.