Security

Last updated: July 2026

How we protect the documents you trust us with.

1.Encryption

Files are encrypted at rest in storage and served only over TLS. Download links are short-lived and cryptographically signed.

2.Tenant isolation

Every document is scoped to your organisation, and ownership is verified on every request — results, downloads and previews included.

3.Access & authentication

Passwords are stored only as salted hashes. Sessions can be revoked instantly (a password change invalidates every existing token). Sign-ups can be gated to admin approval.

4.No training on your data

Your content is never used to train AI models, and third-party retention is disabled where the provider allows it.

5.Data location

Storage is in the EU (Cloudflare R2 EU jurisdiction) and compute is in Germany.

6.Confidential mode

For sensitive material, Confidential mode keeps verification fully offline — no web search and no slide images leaving the platform — while still reconciling your deck against your own source model.

7.Retention control

You decide how long originals are kept; a scheduled job enforces automatic deletion, and manual deletion removes every associated object.

8.Backups

Backups are stored in the same EU jurisdiction with limited retention and are periodically restore-tested.

9.Reporting a vulnerability

Found a security issue? Please email security@facticy.com — we appreciate responsible disclosure.