Security
Last updated: July 2026
How we protect the documents you trust us with.
1.Encryption
Files are encrypted at rest in storage and served only over TLS. Download links are short-lived and cryptographically signed.
2.Tenant isolation
Every document is scoped to your organisation, and ownership is verified on every request — results, downloads and previews included.
3.Access & authentication
Passwords are stored only as salted hashes. Sessions can be revoked instantly (a password change invalidates every existing token). Sign-ups can be gated to admin approval.
4.No training on your data
Your content is never used to train AI models, and third-party retention is disabled where the provider allows it.
5.Data location
Storage is in the EU (Cloudflare R2 EU jurisdiction) and compute is in Germany.
6.Confidential mode
For sensitive material, Confidential mode keeps verification fully offline — no web search and no slide images leaving the platform — while still reconciling your deck against your own source model.
7.Retention control
You decide how long originals are kept; a scheduled job enforces automatic deletion, and manual deletion removes every associated object.
8.Backups
Backups are stored in the same EU jurisdiction with limited retention and are periodically restore-tested.
9.Reporting a vulnerability
Found a security issue? Please email security@facticy.com — we appreciate responsible disclosure.