FeaturesSecurityPricingCompareDevelopersBlogStart Free

Data Residency and Compliance

There is no Gulf region, and no date for one.

The buyers who care about this check. So this page starts with what we do not have, names every country a byte touches, and then describes the controls that are real. Rule us out here if you need to.

Every party that touches the data

This is the list from our Trust Center, reproduced here so a reviewer working through a Gulf questionnaire does not have to go looking. We give advance notice of material changes to it.

Subprocessors and the country each operates in, as published on the Sifrsys Trust Center.
CriterionPurposeCountry
SupabaseDatabase, authentication, storageUnited States
VercelApplication hosting and CDNUnited States
HetznerDocument processing, transientGermany
AnthropicAI responsesUnited States
Voyage AIText embeddingsUnited States
StripePayments, billing data onlyUnited States
ResendTransactional emailUnited States
TwilioSMS and WhatsApp invitationsUnited States
GoogleOAuth sign-inUnited States
Subprocessors and the country each operates in, as published on the Sifrsys Trust Center.

Read that list as a Gulf compliance officer would. Deal content leaves the United States only for transient processing in Germany, and it reaches two US AI providers as part of answering questions. Our Trust Center states that this content is not retained by those providers and is never used to train models. If sending deal content to a US AI provider under any terms is disqualifying for your mandate, that is a clean reason to stop reading.

What happens to a document

  1. Upload
    TLS 1.3 in transit, into a private bucket. United States
  2. Process
    Parsed and chunked, transient, not stored at rest. Germany
  3. Index
    Embeddings generated by a US provider, stored with the room
  4. View
    Server-resolved permission, watermark burned in, view written to the log
The path a document takes, with the country of each hop. Nothing on this path sits in the GCC.

Encryption is AES-256 at rest and TLS 1.3 in transit. Buckets are private and never publicly readable, so a document URL is not a credential. Every view is written to a SHA-256 hash-chained audit log whose integrity is verified on a schedule, which means tampering with the record is detectable rather than merely discouraged. You can export that log from your own room, so the record is something you verify rather than something we describe.

The question behind the question

Gulf security reviews have started asking where the AI permission check sits, which is the right question, because the same rule is either a control or theatre depending on the layer it lives in.

  • In the system promptbypassable

    Asking the model not to mention documents the user cannot see. A model can be argued out of an instruction.

  • In application code, after retrievalbypassable

    The rows already left the database. A mistake in the calling code returns them.

  • Inside the SQL queryenforced

    Filtered on tenant id and a per-participant document access function, so an unauthorised chunk is never read out.

  • Row-Level Security in the databaseenforced

    Tenant isolation enforced below the application, so an application bug cannot cross the boundary.

Where a permission rule can sit for AI retrieval. Only the bottom two survive a bug in the layer above them.
30
Chunks of verbatim deal text, across 13 documents, that an unrelated signed-in user retrieved before the July 2026 lockdown
Measured. The incident that prompted the lockdown.
In-query
A chunk outside the participant's permission is never selected, so no later code path can return it
Structural, not empirical: both predicates asserted against pg_proc.prosrc on every push.
42501
SQLSTATE returned to a direct call from the published anonymous key
Denial suite, tests/security/org-isolation.test.ts, run in CI on every push

Proving who saw what

A residency question is usually a proxy for a leak question. Watermarks are burned into the page image on the server before encoding, tiled across the page, carrying participant name, email, IP and timestamp. Two participants viewing the same page receive different bytes. Delete every overlay element in the browser and the identity is still in the pixels, because it was never an overlay. The worst of 64 sampled 25 percent crops retained 11.7 percent of the watermark ink with all four fields legible, and the mark survives JPEG quality 50 and a 50 percent downscale.

Two things we will not soften

Chat history persists in your room. Some vendors say conversations are not stored. Ours are, on purpose, because a record with gaps in it is not an audit trail. What our Trust Center states separately is that content is not retained by our AI providers and is never used to train models.

And the honest summary of the residency position is short. We can tell you precisely which country every subprocessor operates in and precisely what is logged. We cannot give you an in-region deployment, a certification badge, or a guarantee about where data sits, because we do not have any of the three. A vendor page that claims all of them is either a different product or a Trust Center you should read more slowly.

Who this is still right for

Cross-border processes where the counterparties are outside the region anyway. Fundraises, board portals and client portals where the constraint is confidentiality rather than jurisdiction. Deals where the documents are Arabic and Hijri-dated and no incumbent renders them properly, which is the problem the Saudi Arabia page measures, and the GCC page extends across the three-decimal dinars.

Plans are published and flat: free tier, Teams at $399 a month, Pro at $999 a month, custom Enterprise, with AI included rather than sold as an add-on and no per-page fees. The 14-day trial takes no credit card, so the cheapest way to test any of the above is to test it. See pricing, and /trust for the compliance table this page draws on.

Residency and Compliance FAQ

The questions a security reviewer sends before the kickoff call.

No. There is no Gulf region and we have no date for one. The primary database, object storage and application hosting run in the United States. Document processing is transient in Germany. If a mandate requires in-region hosting, we do not meet it and you should rule us out rather than run a three-week security review to reach the same conclusion.
No. We hold no SOC 2 certification of any type and no ISO 27001 certification, and no audit engagement is signed. We do not display a badge for an engagement that has not completed. No independent penetration test has happened either.
No. We hold no attestation or certification under the Saudi PDPL or under any other national or free-zone data protection regime in the Gulf. This page is a factual account of where data sits and what the software does. It is not legal advice and we are not your counsel.
Yes, and we would rather say so than let you discover it. Chat history persists in your room, which is what makes the record complete and what makes an audit trail worth having. What our Trust Center states about the providers is separate: content is not retained by our AI providers and is never used to train models.
The retrieval filter runs inside the SQL query, on tenant id and a per-participant document access function, so a chunk the participant cannot open is never returned to the model in the first place. That exclusion is structural, asserted against the deployed function's source in pg_proc.prosrc on every push, alongside a denial suite that counts only SQLSTATE 42501 as a pass. The measured half is the failure that prompted the lockdown: before July 2026 an unrelated signed-in user retrieved 30 chunks across 13 documents of verbatim deal text. A permission rule written into a prompt is not a control, because a model can be argued out of it.
The subprocessor list and its countries are public on our Trust Center. The audit log exports from your own room, so you can verify the record rather than take our description of it. The permission test above is one you can reproduce inside a room you control. What you will not get is a certification badge, because we do not have one.

Verify It Yourself

Open a room and export the audit log.

Invite a second participant, restrict a folder, ask the AI about it, and read the log. Fifteen minutes on the free tier tells you more than a questionnaire.

Free to start · No per-page fees · No credit card required

Start Free