Where your documents live

Three postures, one pipeline. Which one you are on changes where bytes rest and who holds the keys — nothing else.

Posture
Individual
One person, trying it on their own work.
Team
A business running its paperwork through us.
Enterprise
Policy says the data does not leave your estate.
Page images
Our storage
Our storage, encrypted at rest
Your bucket
Encryption keys
Managed by us
Managed by us, or yours on request
Your KMS
Retention
Until you delete it
Your policy
Your policy, including keep nothing
Deployment
Shared
Shared
Shared or private

What actually leaves your infrastructure

Reading handwriting means a model has to see the page. Even on Enterprise, where the image rests in your bucket under your key, the bytes pass through our memory and through the model provider’s API in order to be read. We do not store them and we contract zero-retention with providers, but we are not going to tell you the page never leaves your network, because that would not be true.

If your policy requires that documents never leave your network at all, you need an on-premise deployment with a local model. Tell us and we will say plainly whether we can serve you yet.

True on every plan

We never train on your documents

Not for our models, not for anyone else’s. It is in the contract, not just the marketing.

Tenants are isolated at the database

Row-level security, tenant-scoped storage, tenant identity on every query path.

Every value is traceable

Each field records where it came from, which model read it, and every change since.

You choose the region

Storage pinned to the US, EU, or GCC. Chosen when the workspace is created.

Questions we have not answered here? Ask us directly — a person replies.