Your evidence is processed in memory, in one region, and not kept.
This page states what the service does with what you send, who can see it, and which controls exist today versus which are planned. Where a certification is not yet held, it says so.
One path, three parties, nothing stored by default.
Metadata: request id, timestamps, token and search counts, cost, the reasoning version and model used, and the participation trace. Enough to bill and to reproduce provenance — not the content.
Inference requests to the model provider, and — only when you enable discovery — web search queries about the counterpart you named. Nothing about Party A is searched.
Subprocessors: Google Cloud (hosting), Anthropic (inference and web search), Stripe (payments). [Link the subprocessor list and DPA when published.]
Available today, and what isn't yet.
Marked plainly so a security review doesn't have to guess.
Shown in full exactly once; stored hashed; listed by prefix, creator, and last use; revoked instantly.
Owner, Admin, Developer, Billing, Viewer. Developers see only their assigned projects; Billing never sees keys.
Email requires verification before anything else. Passwords are stored as salted PBKDF2-HMAC-SHA256 hashes. Sessions are server-side and revocable.
Organization creation, key creation and revocation, payment method changes, and sign-ins — with actor, IP, and timestamp.
Cards are entered on Stripe's hosted page and stored with Stripe. We hold a payment method reference, not a number.
Verification before payment, a rate limit for the first 24 hours, a small pre-charge ceiling, and a $1 first charge that validates the card before compute burns.
Not available at launch. Compensating controls: allowed-email-domain invitations, one-click member removal that revokes sessions and lists that member's keys for rotation, and the audit log. [Target dates.]
Per-project key allowlists, monthly budgets with alerts, and a hard cap. [Target dates.]
Controls now. Certifications when they're earned.
Every assessment names its reasoning revision and model. Revisions are immutable, so a reading can be attributed months later — without the content, which was never kept.
Synthetic, non-sensitive canary assessments run against production on a schedule, with uptime checks and alerting. Real customer content is never sampled for validation.
Running a vendor review? Ask for the security overview and the subprocessor list.
Grant your reviewer the Viewer role and they can read the audit log and settings without changing anything. Report a vulnerability to [security@domain].