Data and security
How we handle your records.
Where your quality records go, who sees them and when they are deleted. Every line here is something we can show you.
- You send exports. We install nothing and never connect to your systems.
- Files come in through a private upload link, not as attachments.
- Each file is opened and checked by a person before it is loaded.
- Processing happens on an encrypted workstation and through Anthropic, our AI provider, which does not train its models on our clients' data.
- Your records get a store of their own; no other customer's data sits beside them.
- Deleted 30 days after your pack is delivered unless you continue with a subscription, or on request at any time, confirmed in writing.
What we accept, and what we do not
We accept quality records: CAPA and 8D, nonconformances, calibration, training, suppliers, documents, audit findings, PFMEAs, control plans, PPAP status, gauge studies and the other registers in our templates. The only personal details we take are names, employee IDs and roles.
Your customers' confidential program data stays with you. We do not want TISAX-labelled material such as customer drawings, CAD, prototype details or vehicle program information beyond what the quality records themselves contain, and we do not accept personal data beyond names, employee IDs and roles. The Pack also cannot process export-controlled (ITAR or EAR) technical data. The fit check asks about restricted data before you pay. Not sure about a record? Ask us before it is uploaded.
Should restricted data reach us regardless, we halt, leave it unprocessed, delete it, and send you written confirmation that it is gone.
Where your data is processed
We check and process your files on an encrypted workstation. For the AI-assisted parts of the analysis, Anthropic is our named subprocessor and handles them with Claude, with model training on our clients' data turned off.
The Audit Defense Pack has no customer login. Your pack reaches you as files, handed over on the review call.
Who sees it
One reviewer, who checks your data and reads every page of the pack, and Anthropic, which processes the analysis for us. Nobody else, your customers included. The Audit Defense Pack Services Agreement binds us to confidentiality, and you keep ownership of your records.
How long we keep it
Your data is deleted 30 days after your pack is delivered unless you continue with a subscription. Ask, and we delete it sooner. Deleting means the files you uploaded, the store built from them and the reports we generated, and we put the confirmation in writing.
What we do not claim
We do not currently hold a TISAX assessment label or third-party security certifications or attestations such as SOC 2 or ISO 27001. If your customer's information security requirements or your own supplier-security process need something specific, tell us on the fit check and we will answer honestly.
This website
Fit check answers go to a server we run ourselves, only so we can answer you. See the privacy notice (draft).
Questions about data handling: email us.