Skip to content

Trust Center

Safeguards implemented in the repository and explicit limitations for the small, closed Oddseal private beta.

These are current repository controls; production configuration and launch evidence still require verification. Oddseal has not completed SOC 2 or another security certification and does not claim GDPR, HIPAA, PCI, residency, or sector-specific compliance.

01

Redaction and human review

Automated detection provides suggestions and can miss sensitive material. A human must review the document and choose what to remove. Oddseal then creates fresh raster-backed pages and fails closed unless the selected targets pass absence, structure, and fidelity checks. A passed check does not prove that every sensitive item was detected.

02

Access and tenancy

  • Email and password authentication with verified email; no OAuth, MFA, trusted-device, or step-up flow in this beta.
  • Database-authoritative seven-day sliding sessions, session revocation, and all-session revocation after password change or reset.
  • Every product request reloads active membership, and tenant-owned database rows use organization-scoped relationships.
03

Data protection and lifecycle

  • Private object storage and short-lived signed access; originals are never used as shared artifacts.
  • Detected values use versioned AES-256-GCM encryption with separated derived-key purposes. Share tokens are stored as hashes.
  • Originals normally purge 1–168 hours after verification, default 72 hours. Document deletion revokes access immediately and targets primary purge within 24 hours.
  • Uploaded documents are not used to train models. External AI is disabled for this beta.
04

Telemetry boundary

Hosted telemetry is limited to allowlisted, content-free events, aggregate metrics, and scrubbed exceptions. It excludes document text, detected values, filenames, customer emails, raw document/share identifiers, bodies, headers, tokens, and full URLs with queries.

05

Known limitations

This is a best-effort beta with one Railway API, one private engine, one processing permit, no uptime SLA, and no region selector. R2 is the only PDF object store and Oddseal is not an archival backup. The Railway engine has outbound network access and weaker runtime containment than the separate production-shaped Compose profile.