Enterprise-Grade Security & Compliance

Built on a foundation of industry-leading standards. Your data is isolated, encrypted, and compliant by design.

PrivateDocs AI runs 100% locally on your own hardware. Your data, documents, and chat history never leave your device. We do not use third-party cloud providers, and no data is transmitted over the internet for AI inference.

SOC 2 Type II
Service Organization Control
HIPAA Ready
Health Insurance Portability
GDPR
General Data Protection Regulation
PCI DSS
Payment Card Industry Data Security

Infrastructure Security

Every layer of our stack is powered by industry-leading providers with proven security certifications.

Local Compute Engine

Your Hardware

AI inference runs 100% locally on your own hardware, with support for Intel, AMD, and Apple Silicon (M1 and newer) or local AMD/NVIDIA GPUs. No third-party cloud providers are used for AI workloads.

  • All models and embeddings run on your own machines
  • No data leaves your device or on-premise network for AI inference
  • Data residency fully under your control — documents, vectors, and chat history remain exclusively on your hardware
  • Offline-capable by design with no external dependencies for core processing

Database & Authentication

Supabase

User data and authentication managed by Supabase with enterprise-grade security.

  • SOC 2 Type II and HIPAA compliant infrastructure
  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption in transit
  • Row-level security and role-based access control
SOC 2 Type IIHIPAA

Payment Processing

Stripe

All payment transactions processed through Stripe's certified infrastructure.

  • PCI Service Provider Level 1 (highest grade)
  • Tokenization for card data protection
  • Real-time fraud detection and prevention
  • SOC 2 Type II certified payment infrastructure
PCI DSS Level 1SOC 2 Type II

Frontend Hosting

Vercel

Application delivered via Vercel's global Edge Network.

  • SOC 2 Type II and ISO 27001 certified
  • DDoS protection and automatic threat mitigation
  • Edge caching for performance and security
  • Automatic SSL/TLS certificate management
SOC 2 Type IIISO 27001

Local Desktop Application

When you use the PrivateDocs AI desktop application, your data never touches our infrastructure for AI processing. All document and chat content remains on your own machines.

On-Device Processing

The PrivateDocs AI desktop app runs a local inference engine on your machine. All document uploads, embeddings, and AI inference occur entirely on your device. No document content, chat content, or personal data is sent to PrivateDocs AI, Supabase, Stripe, or any other subprocessor for AI processing.

You remain the data controller for documents and content processed on your devices; our role is limited to providing the desktop software and handling limited account and billing data as described in our Privacy Policy and DPA.

Your Data, Your Control

We believe you should have complete control over your data. Our architecture is designed with privacy at its core.

Zero Data Retention for AI Workloads

AI models automatically wipe memory after each inference session. Document content is never retained on GPU infrastructure beyond active processing.

Data Residency

All data, documents, and chat history remain on your own hardware. There are no third-party cloud providers in the AI inference path, so data residency is fully under your control.

GDPR Rights Support

Full support for "Right to be Forgotten," data portability, and access requests. Export your data at any time in machine-readable formats.

Native OS Security

Fully compatible with enterprise-mandated Full Disk Encryption (macOS FileVault & Windows BitLocker). Account and billing data in transit is protected by TLS 1.3.

Zero-Knowledge Architecture

What We Can See:

  • • Account metadata (email, license status)
  • • Basic billing and payment metadata (handled primarily by Stripe)
  • • Limited system logs (errors and performance metrics for the desktop app and activation APIs)

What We Cannot See:

  • • Document content or file names
  • • AI prompts or generated responses
  • • Any data processed by the AI models

Questions About Security or Compliance?

Our security and compliance team is here to help. We can provide additional documentation, answer questions about our infrastructure, or schedule a security review call.