Three postures, one pipeline. Which one you are on changes where bytes rest and who holds the keys — nothing else.
Reading handwriting means a model has to see the page. Even on Enterprise, where the image rests in your bucket under your key, the bytes pass through our memory and through the model provider’s API in order to be read. We do not store them and we contract zero-retention with providers, but we are not going to tell you the page never leaves your network, because that would not be true.
If your policy requires that documents never leave your network at all, you need an on-premise deployment with a local model. Tell us and we will say plainly whether we can serve you yet.
Not for our models, not for anyone else’s. It is in the contract, not just the marketing.
Row-level security, tenant-scoped storage, tenant identity on every query path.
Each field records where it came from, which model read it, and every change since.
Storage pinned to the US, EU, or GCC. Chosen when the workspace is created.
Questions we have not answered here? Ask us directly — a person replies.