Security and data handling
Your client's drawings stay
your client's drawings.
This page is written for the person who has to approve us, not for a marketing audience. It sets out exactly where project information goes, who can reach it, how long it survives, and what we have committed to in writing.
Version 1.0 · Last reviewed date · Owner name, role
In short
Six commitments
We do not train on your work
Your documents, drawings and prompts are never used to train or fine-tune any model, by us or by our model providers. It is a contract term, not a setting you have to find and switch off.
Files are deleted, not stored
By default a drawing set or a report is processed and then destroyed. Retention is something you switch on, not something you switch off.
Processing stays in the UK
Project information is processed in UK infrastructure. Any transfer outside the UK is named below, with the legal mechanism that covers it.
Nobody here browses your files
Our engineers have no standing access to customer data. Access requires named, time-limited authorisation, and it is logged.
The engineer signs, not the software
Every output is a proposal for a competent engineer to accept, amend or reject. We never issue, submit or approve anything.
You can take it in-house
Where your policy requires it, the platform can be deployed inside your own environment, so project files never leave your network.
The journey
What happens to a drawing set
The single question most security reviews come down to is where a file actually goes. This is the full path, in order.
-
Upload
The engineer uploads through the web app or the Word plug-in. The file travels over TLS TLS version and is bound to your firm's workspace the moment it arrives.
-
Held
The file is held in encrypted working storage in a UK region, isolated to your firm. It is never written to shared or unencrypted storage and never leaves the workspace boundary.
Encrypted at rest · cipher · UK region -
Prepared
Text is extracted, drawing sheets are tiled for reading, and the relevant published guidance is retrieved from our own corpus. personal-data removal: does this control exist yet?
-
Analysed
Prepared content is sent to our model providers for inference only. Those providers operate under zero data retention terms: they do not store the request, do not log its content, and do not train on it. Each one is named in the sub-processor list below.
Inference only · Zero retention · No training -
Returned
Findings, markups, tracked changes and calculations are assembled and returned to the engineer, each one traceable to the guidance clause or the calculation method behind it.
-
Destroyed
The uploaded file and every intermediate artefact are deleted within how long after the job finishes? of the job completing. Unless your firm has explicitly enabled the precedent library, nothing about the project survives the session.
Deletion is the default state
Retention
What we keep, and what we never keep
There are exactly two modes. Ephemeral is the default. The precedent library is opt-in, per firm, and can be switched off and purged at any time.
| Item | Ephemeral (default) | Precedent library (opt-in) |
|---|---|---|
| Uploaded documents and drawings | Deleted after processing | Held in your isolated store |
| Extracted text and intermediate files | Deleted after processing | Deleted after indexing |
| Outputs and findings | Held how long? so you can retrieve them, then deleted | Held until you delete them |
| Operational logs | Metadata only, no document content, how long? | Metadata only, no document content |
| Used to train or improve any model | Never | Never |
| Visible to any other customer | Never | Never |
| Deletable on request | Already gone | Yes, permanently, within how long? |
On the precedent library. When you enable it, it stores your firm's own past strategies so the tool can match your house style and your standard clauses. It serves your firm and nobody else. It is not pooled, not shared, and not used to improve a model that any other customer touches. If you close your account it is deleted along with everything else.
Who can reach it
Access control
Our people
- Engineers have no standing access to production systems
- Development and testing environments contain no customer data
- Support access requires named, time-limited, per-incident authorisation, and is logged
- All administrative access requires phishing-resistant multi-factor authentication
- Every change to production is reviewed by a second person
Your people
- Access is scoped to your firm's workspace
- single sign-on and SAML: offered, or not yet?
- project-level access controls: offered, or not yet?
- An audit trail of every document processed, available to your administrators
- You decide what is uploaded, and you can delete it
Supply chain
Sub-processors
These are the third parties involved in delivering the service. We maintain this list, we notify customers before it changes, and we hold each party to terms consistent with the commitments on this page.
| Provider | Purpose | Region | Terms |
|---|---|---|---|
| model provider | Model inference | region | Zero retention, no training |
| second model provider, if any | Model inference | region | Zero retention, no training |
| cloud host | Compute and storage | UK region | Encrypted, isolated per firm |
| Google (Google Workspace) | Sign-up records and outbound email | EU and US, UK IDTA | No training |
| Calendly | Demo scheduling, only if you book one | US, UK IDTA | No project data |
AI risk
The risks specific to this kind of software
Your data cannot end up in a model
Customer content is used at inference time and nowhere else. Because nothing is ever used for training or fine-tuning, there is no mechanism by which your project information could surface in another customer's session.
Malicious content in documents
A document can carry text intended to manipulate an AI system. We apply defences at the boundary, and the deeper protection is structural: every finding is traceable to a source an engineer can open and check.
Wrong answers
Answers are grounded in published guidance with the source shown. Calculations run deterministically in code rather than being produced by a model, so the same inputs always give the same result.
The tool never acts alone
It drafts, reviews and proposes. It does not issue, submit, approve or sign anything. Professional judgement and responsibility stay with the engineer throughout.
Assurance
Certifications and independent testing
We would rather show you where we are than imply more than we hold.
| Standard | Status | Target |
|---|---|---|
| Cyber Essentials | status | target date |
| Cyber Essentials Plus | status | target date |
| UK GDPR and the Data Protection Act 2018 | Compliant as data processor | Ongoing |
| ICO registration | registration number | Current |
| Independent penetration test | status | date |
| ISO 27001 | planned, or not yet | target date |
| ISO 42001 (AI management) | planned, or not yet | target date |
In writing
What we commit to contractually
These are standing terms, offered to every customer by default. They are not concessions you have to negotiate for and they do not vary by contract size.
| Our role | Data processor under Article 28 of the UK GDPR. You remain the controller. |
|---|---|
| Data processing agreement | Offered as standard with every subscription. You do not have to ask. |
| No training | We will not use your content to train or fine-tune any model, and we impose the same term on our providers. |
| Breach notification | We notify you within hours of becoming aware, so you can meet your own 72 hour duty to the ICO. |
| Deletion | On request or on termination, your data is deleted within how long? and we confirm it in writing. |
| Sub-processors | Register maintained and published. We give how much notice? before adding one, and you may object. |
| Data location | Processing in the UK. Any transfer outside it is covered by the UK IDTA or the UK Addendum to the EU SCCs. |
| Evidence | We answer security questionnaires and provide evidence of our controls on request. |
Questions
What review teams usually ask
Where is it hosted and processed?
Application, storage and processing sit in UK region and provider. Model inference runs with the providers listed above. If any processing happens outside the UK we say so, and it is covered by the UK IDTA or the UK Addendum to the EU SCCs.
Do you train on our documents?
No. Not us, and not our model providers. Content is used at inference time and for nothing else. It is a contractual term in your agreement rather than an account setting, so it cannot be changed without your knowledge.
Who at FireStrategy.ai can open our files?
By default, nobody. Our engineers have no standing access to production data, and our development environments contain no customer data. If you raise a support issue that requires access, it is granted to a named individual, time-limited, logged, and the log is available to you on request.
Our appointments restrict sharing client information with third parties. How does that work?
You stay in control of what is uploaded. We act as your processor under a written agreement, we do not use the information for any purpose other than delivering the service to you, and we delete it. Where an appointment or a client requires that information never leaves your infrastructure, use the self-hosted deployment, in which case we never receive it at all. We are happy to review specific confidentiality wording with you.
Is there anything you cannot delete?
Two narrow cases, and you should hear them from us rather than find them. Where content is flagged by a model provider's automated safety systems, that provider may retain it for a period set by their own policy, whatever our zero-retention arrangement says. And where we are subject to a legal hold or a statutory obligation, we must keep what the law requires. Neither is discretionary, and neither is used for any commercial purpose. Everything outside those two cases is deleted as described above.
What happens if we stop using it?
Your data is deleted within how long? of termination and we confirm it in writing. You can export your outputs before you go. There is no residual copy and nothing is kept back for any purpose.
How often is this tested?
penetration testing frequency, internal review, dependency scanning, and how findings are tracked to closure
What if something goes wrong?
We maintain an incident response process, notify affected customers within hours of becoming aware, and follow up with a written account of what happened, what was affected and what we changed. Report a concern to security contact address.
Reviewing us?
Ask for the data processing agreement, the sub-processor register, our answers to your security questionnaire, or a call with the person who built the system. Write to security contact address and we will come back within N working days.