Trust & privacy

Your data is yours alone.

Hosted and stored in the EU, encrypted at rest, and never used to train a shared model. Every claim below names the mechanism that enforces it, so your security team can verify it for themselves.

How PolicyMate protects your data

VERIFIABLE OUTPUT

A fabricated citation can't render.

PolicyMate only cites a document it actually read. Every reference resolves against the real record and against your permissions as the answer renders, and anything that doesn't resolve never reaches your screen.

ACCESS CONTROL

Two-factor, mandatory if you say so.

Your admins require two-factor authentication across the organisation and restrict sign-ups and invitations to your own email domain. New passwords are checked against a breached-credential corpus before they're accepted.

STAFF ACCESS

Nobody here can open your workspace.

Our engineers and support team hold no standing access to your data. If you want hands-on help you grant it yourself, for a window you set in hours, and it expires on its own.

AUDIT TRAIL

A log even we can't edit.

Sign-ins, lockouts, permission changes and security settings are written to an append-only log your own admins read and export. The database itself refuses to update or delete those rows. Not even our engineers.

ENCRYPTION

Encrypted before it reaches the database.

TLS in transit and AES-256 at rest is the baseline. Above it we encrypt assistant conversations, model reasoning traces and integration credentials at the application layer, so database access alone does not read them.

ISOLATION

One boundary, enforced everywhere.

Tenant scoping is enforced globally rather than left to each query, and the same constraint governs search, so search can't surface what the database wouldn't. Those boundaries carry their own automated tests, so a change that quietly widened access fails the build.

Commitments

Eight guarantees, in writing.

Nothing here is new. Your counsel gets the same answers, on paper, whenever they ask.

WE NEVER
Train on your data.

No training pipeline, no model weights, no fine-tuning. There is nothing here to train.

Sell it.

Not to advertisers, not to data brokers, not to anyone.

Show your prompts to reviewers.

No contractors, no annotators, no data-labelling firms read your work.

Copy your prompts into our logs.

Prompts and responses never reach audit records, metrics or monitoring. They stay in your conversation history, encrypted.

WE ALWAYS
Name every sub-processor.

The list is public, and you can subscribe to written notice ten days before it changes.

Delete when you say delete.

Immediate and user-controlled, cascading to the derived artefacts most vendors forget: vector embeddings and search-index entries.

Tell you within 48 hours.

Written notice to your named contact on detection, then updates as we investigate and a post-incident report.

Complete your questionnaire.

Send us yours and we'll fill it in, including the gaps.

The specifics

What's in place today.

Enterprise and legal buyers work down this list first. Where we're not there yet, it says so.

Storage is EU-only. Inference is worth being plain about: our primary model providers run globally, so prompts are processed outside the EU under Standard Contractual Clauses. Our OCR provider for public documents is EU-based.

STORAGE & BACKUPS IN THE EU
NEVER USED TO TRAIN SHARED MODELS
TLS IN TRANSIT · AES-256 AT REST
CONVERSATIONS ENCRYPTED AT THE APPLICATION LAYER
ROLE-BASED ACCESS CONTROL, FAILS CLOSED
TWO-FACTOR AUTH, ENFORCEABLE ORG-WIDE
APPEND-ONLY SECURITY LOG, EXPORTABLE
INCIDENT RESPONSE PLAN · 48-HOUR NOTIFICATION
DPA, SCCs & PUBLIC SUB-PROCESSOR LIST
WORKING TOWARD
ISO 27001 CERTIFICATIONROADMAP
SOC 2 TYPE IIROADMAP

Security questions

What security teams ask first.

Your security team will have more than these. Bring them to the call.

Book a walkthrough

No. We run no training pipeline and hold no model weights, so there is nothing here to train. Every AI call is stateless inference under terms that exclude your data from training.

Stored in the EU. Inference is the exception worth naming: our primary model providers run globally, so prompts are processed outside the EU under Standard Contractual Clauses.

No. Nobody here holds standing access. If you want hands-on help from support, you grant it yourself for a window you set in hours, and it expires on its own.

We delete your workspace from live systems within ten business days, including derived data like embeddings and search entries. Encrypted backups roll off within a month.

Both are on the roadmap, and we won't claim either before it's real. The controls on this page were built against those frameworks, and we complete your security questionnaire in writing.

Bring your security team. We'll bring the answers.

We'll answer whatever they need to sign this off, in writing.

20-MINUTE WALKTHROUGH · NOTHING TO CONFIGURE · MINUTES A DAY