Trust & Security

Each customer lives in their own locked container. Your project is its own drive; search and access can only ever show a person what their own container holds. Customers are never members of each other's drives — cross-contamination isn't prevented by policy alone; it's impossible by structure.

Your originals are sacred. The system writes beside your files, never over them. Every run appends to an audit log that cannot be edited after the fact.

Minimal operator access. Processing runs under dedicated system identities, not personal accounts; the operator's master key is being split into one key per customer. Support access to document content happens only when you ask for it, is logged, and ends when the issue does.

Backups you can believe. Nightly encrypted backups — with a monthly scripted restore test that verifies row counts and file hashes. A backup that's never been restored is a hope; ours is a rehearsal.

Isolation in depth. Per-customer database schemas; per-document sha256 fingerprints; sign-in with password plus mandatory two-factor authentication and recovery codes; HTTPS everywhere.

No lock-in, ever. Every artifact we produce is an ordinary file in your own Google Drive. Leaving costs nothing and loses nothing.