Security & Trust

Security is a first-class product surface,
honestly disclosed, no marketing hand-waving.

Your P&IDs, isometrics, HAZOP registers and NOC-tier deliverables are among the most sensitive documents in your business. Below is exactly where they live today, where they will live at enterprise scale, and every subprocessor in between. Nothing is claimed as achieved until it is auditor-signed.

Current state

Pilot workloads on Vercel + Railway. Pilots under NDA and scoped to redacted documents.

Enterprise deployment

EU-pinned Postgres (Supabase Frankfurt) + Fly.io Frankfurt/ London on the enterprise roadmap. Committed, dated below.

Current infrastructure

What we run today, on the record.

The pre-enterprise stack. Everything below is production today and covered by NDA and DPA for pilot customers.

LayerVendorRegionAttestations
Marketing siteVercelGlobal CDN (edge)SOC 2 Type II · ISO 27001 · GDPR
Pilot portal (compute)RailwayUS-East (current) · EU pinning on roadmapSOC 2 Type II
Pilot portal (database)Embedded SQLite (on Railway volume)Co-located with computePilot-scale only · migrating to Supabase Postgres (EU) — see roadmap
Document storageRailway persistent volumeCo-located with computeEncrypted at rest · migrating to Supabase Storage (EU) — see roadmap
AI inferenceAnthropic (Claude)US · EU-region routing available via Bedrock on roadmapSOC 2 Type II · zero training on customer data (contractual)
PaymentsStripeIreland (EU) for EU customersPCI DSS Level 1 · SOC 2 Type II

Full subprocessor list — including AI providers, email, payments, DNS and analytics — is published at /subprocessors. Data Processing Addendum available on request: security@specsense.ai.

Procurement-ready answers

The six questions your security team will ask.

Answered inline, no NDA required to read.

Do you train models on our documents?

No. Never. Customer documents are processed for the review that generated them and are never used to train, fine-tune, or retrain any model. This is contractual with Anthropic (our current AI provider) and contractual with you via our DPA.

Where does the data live today?

Today, pilot workloads run on Vercel (marketing site, global CDN) and Railway (portal + document storage, currently US-East). Pilots are covered by NDA and DPA, with a strict scope of redacted documents. The full current-stack table is above.

Where will the data live at enterprise scale?

EU-pinned Postgres on Supabase (Frankfurt, eu-central-1) plus Fly.io compute (Frankfurt fra + London lhr) are on the committed enterprise roadmap — dated in the compliance table below. UK, EU, and UAE data-residency options follow SOC 2 Type I. Regional-only pinning available on Enterprise.

What happens to our IP?

It remains yours. All outputs — findings, comment registers, redlines — are your intellectual property. We assert no rights over inputs or outputs beyond the minimum license needed to deliver the review.

How is data isolated between customers?

Per-tenant logical isolation on all storage today. Row-level security (RLS) with per-tenant encryption keys ships alongside the Postgres migration on the enterprise roadmap. No cross-customer query paths. Every document access is logged with actor, timestamp, and purpose.

Where does the AI stop and the engineer start?

The AI produces candidate findings. A Chartered Engineer triages severity, discards false positives, and signs the final register. You are never shown machine output without human review on supervised tiers.

How do we get our data out?

One click. Full export of all documents, findings, and comment registers as PDF, CSV, and native formats. Deletion on request within 30 days, with written confirmation and destruction attestation.

Do you have a DPA and subprocessor list?

Yes. Data Processing Addendum available on request at security@specsense.ai. Public subprocessor list at /subprocessors — every third party that touches customer data is named there.

Security posture

Five pillars, no hand-waving.

Encryption everywhere.

Data is encrypted at rest and in transit. No exceptions, no legacy paths.

  • AES-256 at rest across storage and backups
  • TLS 1.3 in transit, HSTS enforced
  • Per-tenant encryption keys on Enterprise (with Postgres migration)
  • Encrypted backups with 90-day retention

Regional hosting on roadmap.

EU-pinned deployment is the enterprise target. Today's pilot workloads run US-East under NDA.

  • Current: Railway US-East for pilot portal (under NDA + DPA)
  • Enterprise target: Supabase Frankfurt + Fly.io Frankfurt/London
  • UK, EU, UAE data-residency options with SOC 2 Type I
  • No cross-region replication by default at any tier

Access is auditable.

Every document access is logged with actor, timestamp, and purpose.

  • Full audit trail for every review action
  • SSO/SAML available on Enterprise
  • Role-based access with least privilege
  • Named Security Point of Contact on Enterprise

Zero training on your data.

Your documents feed reviews, never model weights.

  • Contractual guarantee, not marketing language
  • No fine-tuning on customer documents
  • No prompt-tuning on customer content
  • Prompt-inspection logs available on request

IP retention.

Everything you send in and everything we send back is yours.

  • Customer owns all inputs and outputs
  • Minimum license needed to deliver the review
  • No downstream use of findings or registers
  • Deletion on request with destruction attestation

Incident response.

If something goes wrong, you hear from us fast and in writing.

  • 4-hour acknowledgement window
  • 24-hour written response commitment
  • Named Security POC on Enterprise
  • Pre-agreed breach notification thresholds
Compliance & hosting roadmap

What we are building, and by when.

Compliance and enterprise hosting on the same timeline — because our buyers ask about them in the same procurement pass. Nothing below is claimed as achieved until auditor-signed or shipped to production.

Now

Pilot infrastructure — Vercel + Railway.

Marketing site on Vercel (global edge). Portal on Railway (US-East, moving to EU pinning). Pilots covered by NDA + DPA. Full stack disclosed above.

Q4 2026

Supabase EU (Frankfurt) migration — Postgres + Storage.

SQLite → Postgres migration with row-level security (RLS) enforced per tenant. Document storage moves to Supabase Storage in eu-central-1. Triggered by first Team-tier or Enterprise-tier contract.

Q4 2026

Formal information-security policy set adopted.

Written policies covering access control, encryption, incident response, vendor management, business continuity, and secure development. Board-signed.

Q1 2027

Fly.io Frankfurt + London deployment.

Compute migrates from Railway US-East to Fly.io fra + lhr regions. EU-first, UK secondary. Removes the last US-region dependency for EU customer workloads.

Q1 2027

SOC 2 Type I audit — targeted.

Point-in-time attestation from a reputable audit firm. Type I confirms controls are designed correctly.

Q3 2027

SOC 2 Type II audit — targeted.

6-month observation window. Type II confirms controls operate effectively over time. This is the badge Enterprise procurement teams actually accept.

Q4 2027

ISO 27001 — targeted.

For customers where SOC 2 is not enough (typically European majors and NOC-tier). Roadmap only; timing subject to demand signal.

Incident response.

If you believe a SpecSense-processed document has been exposed or misused, contact security@specsense.ai. We commit to acknowledgement within 4 business hours and a written response within 24 hours.

Enterprise customers receive named Security Point of Contact, documented SLAs, and pre-agreed breach notification thresholds.

Standards handling

How SpecSense treats codes, standards and client specs.

Full detail on How it works. The short version, for procurement:

Client spec is authoritative.

Your project spec (ADNOC ES, SAES, DEP, GS, TR, or company standard) is uploaded at onboarding and pinned per revision. Every finding cites the exact clause and page from the document you supplied.

Base codes: AI baseline + CEng check.

For public codes (ASME, API, ASTM, ISO, DNV, NACE, IEC) v1 uses the model’s baseline knowledge to draft findings. A chartered engineer validates each citation against the current edition before the register is released. No unverified base-code claim leaves the portal.

Licensed digital libraries — enterprise, Q4 2026.

Full ASME / API / ASTM / ISO / DNV / NACE licensed corpora with per-clause traceability are on the enterprise roadmap. Priced into that tier because publisher enterprise licences are six-figure annual costs. Available on request during pilot conversations.

Ready to run a supervised pilot?

48 hours. Chartered-engineer sign-off. Data isolated per pilot, covered by NDA and DPA.