Trust and security
Full hosting in the EU (Google Cloud, europe-west1); encryption in transit (TLS) and at rest; sessions protected with encrypted cookies (Fernet); Google OAuth and Firebase authentication; private dossiers by default with sharing only via signed links that expire in 15 minutes; storage without public access (adversarially verified); minimization by design in document reading; atomic credit reservation with automatic refund on failure; logging and continuous monitoring of the infrastructure; restricted internal access (least privilege).
Sub-processors
Google Cloud EMEA Ltd. — hosting and database (EEA, europe-west1) · Google (Gemini API, via Google Cloud) — AI processing of texts/documents · Resend, Inc. — transactional emails (USA, with Chapter V safeguards).