Security & compliance

Confidentiality is the architecture, not an addendum

Built for the rigor of clinical research and regulatory work. Here is exactly how your documents stay protected from upload to delivery — ready for your legal and compliance due diligence.

Anonymization before the cloud

Names, IDs, emails, phones and license numbers become reversible codes (⟦PERSON_1⟧) during processing, before anything reaches the AI model. The AI never sees identifiable data.

Data in Brazil · LGPD

Database and files in the São Paulo region (sa-east-1). Processing compliant with Brazil's LGPD, with a legal basis and a recorded consent trail.

NDA + DPA before the first upload

No document is accepted without an active confidentiality (NDA) and data-processing (DPA) agreement. The contract is the gate.

Automatic deletion in 60 days

Your files are automatically deleted after 60 days — or sooner, at any time, at your request.

No AI training on your data

Your documents are never used to train models. AI provider under a contractual no-training clause.

Encrypted anonymization map

The link between code and real data stays encrypted in the database, in your environment, and never leaves for the cloud. Restoration happens only at delivery.

For your due diligence

  • Data residency: Brazil (Supabase, São Paulo / sa-east-1).
  • LGPD legal basis with a consent trail (date, IP, version, user).
  • Reversible PII anonymization before any cloud processing.
  • NDA + DPA available for signature before onboarding.
  • Maximum 60-day retention; deletion on demand.
  • No-training clause with the AI provider.
  • Multi-tenant access control (per-company isolation).

Need the documents for your legal team?

We'll send the NDA and DPA for review and answer your security questionnaire.

Talk to us