SOC 2 Type I scheduled
Annual audit engagement scheduled with a qualified firm. Type II observation begins immediately after Type I issuance. Report available to prospective customers under mutual NDA.
Your inspections carry legal weight. The tools that produce them should be held to the same standard.
Annual audit engagement scheduled with a qualified firm. Type II observation begins immediately after Type I issuance. Report available to prospective customers under mutual NDA.
All data at rest encrypted by Supabase. TLS 1.2+ in transit with HSTS preload. OAuth tokens and PE signing-certificate passwords are AES-256-GCM encrypted.
Primary database and storage in us-east-1. No cross-border transfer by default. Enterprise customers can require residency commitments in their DPA.
Every admin action, key issuance, webhook delivery, and login attempt is written to an append-only audit log. Seven-year retention.
The specifics of how every inspection record, signed report, and customer conversation is scoped, protected, and observed.
Audio + transcripts
Stored in your firm's isolated tenant. Exportable any time. Deleted on contract end.
Observations + reports
Row-level-security scoped by organization. Retained until you delete them. No cross-firm access is possible.
Style profile
Per-firm partition. Derived from your own reports. Deleted within 30 days of contract termination.
Login + audit events
Immutable. Retained for seven years to satisfy typical compliance and AHJ-dispute windows.
No AI training on customer data
Anthropic and OpenAI endpoints called under zero-retention terms. Customer voice and transcripts never contribute to shared models.
No training on your data
Your firm's audio, transcripts, and reports are never used to train shared models. Anthropic Claude and OpenAI Whisper are called under zero-retention endpoint terms.
Your style profile is yours
House-voice style profiles live in a per-firm partition. Cancel the contract and we delete the derived weights within 30 days.
Vendor transparency
We use Anthropic Claude (Haiku 4.5 for extraction, Opus 4 for draft) and OpenAI Whisper for speech-to-text. Both pipelines run under zero-retention terms.
Human review on request
Every draft is optionally routable to a senior reviewer or licensed PE before an inspector can seal. Configurable per project type.
Found a security issue? Tell us first.
We acknowledge good-faith reports within one business day.