Only extracted text reaches our API — with a no-log header ensuring it's immediately discarded. No files stored. No AI training.
Data flow
PDFs rendered via PDF.js. DOCX, XLSX, EML, MSG parsed client-side. No data leaves the browser.
First-pass regex catches emails, phones, NI numbers, sort codes. All local.
Extracted text — not the original file — sent over TLS 1.3 with anthropic-no-log: true headers.
Claude classifies PII types and returns results. Text not used for training and not retained.
Spans returned to browser. Document content never left. Results stored in IndexedDB locally.
Redacted file rendered client-side with █ blocks. Downloaded to your device. No copy stored anywhere.
Data boundary
Infrastructure
All partners maintain SOC 2 Type II certification.
Compliance
Built to support privacy regulations across jurisdictions.
ISO 27001 certification in progress (target Q3 2026). SafeRedact's architecture provides a smaller attack surface than most certified cloud tools.
We're happy to walk through our security model with your privacy or security team.