SafeRedact

Trust Center

How SafeRedact handles your documents, your text and your records.

Every statement on this page is written in the words the data processing agreement uses and can be checked against the product. Documents are read and redacted in your browser and are never uploaded. Only extracted text is sent for detection, and no document is stored on our servers.

Architecture

Extraction, OCR, review, redaction and export all run in the browser tab. The detection service receives extracted text and returns detections. Nothing else leaves the machine.

In your browser

File extraction for all 11 file types, OCR of scanned pages, the review workspace, burned-in PDF redaction, and assembly of the export ZIP. Working state is checkpointed locally so a long case survives a closed tab.

Detection service

Receives extracted text in sections and returns detections. Two layers: pattern matching for structured identifiers and an AI layer for names and personal details in prose. Neither layer redacts anything on its own.

Our servers

Authentication, organization settings, entitlements and case audit metadata (file counts, timings, the processing route). No document content, no extracted text, no redacted output.

Data handling and retention

DataWhere it goesHow long it is kept
DocumentsNever uploaded. Read and redacted in the browser.Not held by SafeRedact at any point.
Extracted textSent to the detection service on the route fixed for your organization.Standard route: never used for training and deleted within 30 days under our commercial terms. EU route: not stored or logged by the AI provider.
Redacted outputBuilt in the browser and downloaded by the reviewer.Not held by SafeRedact at any point.
Case audit metadataOur database (Supabase). File counts, timings, route, attestation events. No file names, no content.For the life of the account, as the customer's own processing record.
Account dataOur database (Supabase). Name, email, organization, roles.For the life of the account.

Processing routes

The route is fixed per organization before a case begins and cannot be changed from inside a case. Every change is recorded in an audit trail.

Standard route

Detection runs on Anthropic Claude. Text is never used for training and is deleted within 30 days under our commercial terms.

EU route

Detection runs on AWS infrastructure within the UK and EU (European regions including London). Text is not stored or logged by the AI provider. Extracted text is not transferred to the United States on this route.

Responsible AI

What the model sees. Extracted text, in sections, with the data subject's identifiers so that they can be preserved. It does not see the original file, the file name, or who is reviewing.

What the model does. Proposes detections with a type and a confidence. It does not redact, does not decide, and does not learn from your text: on the standard route it is never used for training, on the EU route it is not stored or logged.

What a person does. Every detection is accepted, rejected or added by a reviewer, by entity or by file. Export waits for the reviewer's attestation, and files with undecided detections are named before the pack is built. No automated decision reaches the disclosure pack.

What is recorded. audit-trail.csv, review-decision-log.csv, a detection report, a subject preservation summary and a processing failure manifest are written into every export, in the customer's hands, not ours.

Sub-processors

ProviderPurposeData
AnthropicAI detection, standard routeExtracted text. Never used for training; deleted within 30 days.
Amazon Web ServicesAI detection infrastructure, EU route, UK and EU regionsExtracted text. Not stored or logged by the AI provider.
VercelHosting and serverless computeRequest handling. Zero persistent storage of document content.
SupabaseAuthentication and databaseAccount data and case audit metadata. No document content.

Agreements

A data processing agreement is in place before a pilot starts. Executed agreements are recorded against the organization with the document version, the executing signatory and a SHA-256 hash of the exact document signed, so the executed text can be produced later, unchanged. Current and previous versions are published at /enterprise/legal.

Certifications

SafeRedact is not separately certified at this time. The infrastructure providers above, Anthropic, Amazon Web Services, Vercel and Supabase, are each independently SOC 2 Type II certified, and because documents never touch our servers, they are the security perimeter that matters. Their reports are available on request.

Practices

Published figures

Every number on the SafeRedact home page is listed here with what it counts, where it comes from and what it does not claim. Figures are restated when they change; none of them is an estimate.

FigureWhat it countsSource and limits
Characters of live DSARs processed to date The total extracted text, in characters, from files processed for customer organizations answering real data subject requests. Internal accounts and test organizations are excluded. Summed from the per-file processing record described under Data handling and retention. That record holds a case identifier, a file index, a user identifier and a character count, and no document content, so the figure can be totalled without reading anything anyone wrote. It is a running total and rises as cases run. It is not a page count and not a file count.
2 GB per mailbox file, up to 25,000 messages The largest mailbox export file the application will open, and the largest number of messages it will expand from one of them. Both limits are enforced in the shipped extractor rather than advertised as guidance. A file above the size limit is refused with an explanation, and a warning appears from 1.5 GB. The 2 GB ceiling exists because the whole file is held in memory while it is expanded. Exports larger than this are handled by setting a smaller package size in Purview, which is covered in the export guide.
933,000 AI detections in a single case The number of detections found and carried through review in one case during scale testing of a 2,000-file corpus. SafeRedact's own testing, not a customer case. The corpus was built with a deliberately high density of personal data, several times what a real mailbox contains, in order to find the ceiling. The figure covers detection, checkpointing and review. It is not a claim about export at that density on the hardware used for the test, and it is not an accuracy rate: no detection percentage is published anywhere.
55 end-to-end checks, passed twice by every release An automated suite that runs a case from sign-in through processing, review, attestation and export, then inspects the exported files. It checks that planted third-party identifiers are absent from every artifact, that the data subject's own details survive, and that the attestation gate stops an export with undecided detections. The suite runs in a real browser against the deployed build, and a release ships only after two consecutive clean runs. A separate set of regression tests runs on every change. Neither suite measures detection quality, which is why review by a person is mandatory before export.

Figures are stated without a date because the first one is cumulative and changes. If you need a figure as at a particular day for a procurement file, ask and we will confirm it in writing.

Reporting a concern

Security or privacy concerns go to support@saferedact.app. Business-day responses. Include the build stamp from the application header where relevant.

Run your next subject access request through it.

One real case under a signed data processing agreement, with support through the first week.