View how our data security measures compare to other providers here.
Encryption in Transit: TLS 1.2 or higher protects data moving between you and our servers.
Encryption at Rest: Your data is secured with industry-standard AES-256 encryption on our servers.
Cryptographic Modules: Our encryption methods are FIPS 140-2 compliant, meeting high government security standards.
We NEVER use your data to train AI models.
Your content is yours alone. It's only used to provide the service you requested, never for training our AI.Core Commitment: We do not use Customer Data to train, retrain, fine-tune, or otherwise improve our AI models.
Logical Segregation: Your data is kept in a logically separate space, identified by a unique tenant ID, to prevent cross-contamination or misuse.
You are in control of your data.
Easily delete your data from our platform at any time. When you delete it, it's gone.On-Demand Deletion: You can delete your data directly through the Service interface whenever you choose.
Full Deletion: When you delete your data, it is removed from our production systems and from our backups within 35 days, and cannot be recovered afterwards.
Account Closure: Closing your account, or a deletion request we have verified, deletes your data the same way, unless we are required by law to retain particular records.
Data stored in the US or EU.
We store your data in either the US or EU to ensure performance and compliance.Customers in the United States are hosted in the United States (Microsoft Azure US East).
All other customers are hosted in the European Union (Microsoft Azure West Europe).
Cross-Border Transfers: Your content stays in the region assigned to you, but some account and service metadata — such as file sizes, in-product actions, and processing error logs — is handled by providers outside it. Where that means a transfer out of the EEA or UK, we rely on Standard Contractual Clauses (SCCs). Select your country above to see the mechanism that applies to you.
We meet top industry compliance standards.
We adhere to major global privacy and security regulations like GDPR, HIPAA, SOC 2, and CCPA/CPRA to keep your data safe and respect your rights.SOC 2 Type 2: Independently audited for Security, Availability, Confidentiality, and Privacy, with continuous vulnerability scanning and annual third-party penetration testing.
GDPR: Compliant with the EU's General Data Protection Regulation for user rights and data handling.
HIPAA: Ready to sign a Business Associate Agreement (BAA) for processing Protected Health Information.
CCPA/CPRA: Compliant with California's key data privacy laws.