FireStrategy.ai

Security and data handling

Your client's drawings stay
your client's drawings.

This page is written for the person who has to approve us, not for a marketing audience. It sets out exactly where project information goes, who can reach it, how long it survives, and what we have committed to in writing.

Version 1.0 · Last reviewed date · Owner name, role

In short

Six commitments

We do not train on your work

Your documents, drawings and prompts are never used to train or fine-tune any model, by us or by our model providers. It is a contract term, not a setting you have to find and switch off.

Files are deleted, not stored

By default a drawing set or a report is processed and then destroyed. Retention is something you switch on, not something you switch off.

Processing stays in the UK

Project information is processed in UK infrastructure. Any transfer outside the UK is named below, with the legal mechanism that covers it.

Nobody here browses your files

Our engineers have no standing access to customer data. Access requires named, time-limited authorisation, and it is logged.

The engineer signs, not the software

Every output is a proposal for a competent engineer to accept, amend or reject. We never issue, submit or approve anything.

You can take it in-house

Where your policy requires it, the platform can be deployed inside your own environment, so project files never leave your network.

The journey

What happens to a drawing set

The single question most security reviews come down to is where a file actually goes. This is the full path, in order.

  1. Upload

    The engineer uploads through the web app or the Word plug-in. The file travels over TLS TLS version and is bound to your firm's workspace the moment it arrives.

  2. Held

    The file is held in encrypted working storage in a UK region, isolated to your firm. It is never written to shared or unencrypted storage and never leaves the workspace boundary.

    Encrypted at rest · cipher · UK region
  3. Prepared

    Text is extracted, drawing sheets are tiled for reading, and the relevant published guidance is retrieved from our own corpus. personal-data removal: does this control exist yet?

  4. Analysed

    Prepared content is sent to our model providers for inference only. Those providers operate under zero data retention terms: they do not store the request, do not log its content, and do not train on it. Each one is named in the sub-processor list below.

    Inference only · Zero retention · No training
  5. Returned

    Findings, markups, tracked changes and calculations are assembled and returned to the engineer, each one traceable to the guidance clause or the calculation method behind it.

  6. Destroyed

    The uploaded file and every intermediate artefact are deleted within how long after the job finishes? of the job completing. Unless your firm has explicitly enabled the precedent library, nothing about the project survives the session.

    Deletion is the default state

Retention

What we keep, and what we never keep

There are exactly two modes. Ephemeral is the default. The precedent library is opt-in, per firm, and can be switched off and purged at any time.

ItemEphemeral (default)Precedent library (opt-in)
Uploaded documents and drawingsDeleted after processingHeld in your isolated store
Extracted text and intermediate filesDeleted after processingDeleted after indexing
Outputs and findingsHeld how long? so you can retrieve them, then deletedHeld until you delete them
Operational logsMetadata only, no document content, how long?Metadata only, no document content
Used to train or improve any modelNeverNever
Visible to any other customerNeverNever
Deletable on requestAlready goneYes, permanently, within how long?

On the precedent library. When you enable it, it stores your firm's own past strategies so the tool can match your house style and your standard clauses. It serves your firm and nobody else. It is not pooled, not shared, and not used to improve a model that any other customer touches. If you close your account it is deleted along with everything else.

Who can reach it

Access control

Our people

  • Engineers have no standing access to production systems
  • Development and testing environments contain no customer data
  • Support access requires named, time-limited, per-incident authorisation, and is logged
  • All administrative access requires phishing-resistant multi-factor authentication
  • Every change to production is reviewed by a second person

Your people

  • Access is scoped to your firm's workspace
  • single sign-on and SAML: offered, or not yet?
  • project-level access controls: offered, or not yet?
  • An audit trail of every document processed, available to your administrators
  • You decide what is uploaded, and you can delete it

Supply chain

Sub-processors

These are the third parties involved in delivering the service. We maintain this list, we notify customers before it changes, and we hold each party to terms consistent with the commitments on this page.

ProviderPurposeRegionTerms
model providerModel inferenceregionZero retention, no training
second model provider, if anyModel inferenceregionZero retention, no training
cloud hostCompute and storageUK regionEncrypted, isolated per firm
Google (Google Workspace)Sign-up records and outbound emailEU and US, UK IDTANo training
CalendlyDemo scheduling, only if you book oneUS, UK IDTANo project data

AI risk

The risks specific to this kind of software

Your data cannot end up in a model

Customer content is used at inference time and nowhere else. Because nothing is ever used for training or fine-tuning, there is no mechanism by which your project information could surface in another customer's session.

Malicious content in documents

A document can carry text intended to manipulate an AI system. We apply defences at the boundary, and the deeper protection is structural: every finding is traceable to a source an engineer can open and check.

Wrong answers

Answers are grounded in published guidance with the source shown. Calculations run deterministically in code rather than being produced by a model, so the same inputs always give the same result.

The tool never acts alone

It drafts, reviews and proposes. It does not issue, submit, approve or sign anything. Professional judgement and responsibility stay with the engineer throughout.

Assurance

Certifications and independent testing

We would rather show you where we are than imply more than we hold.

StandardStatusTarget
Cyber Essentialsstatustarget date
Cyber Essentials Plusstatustarget date
UK GDPR and the Data Protection Act 2018Compliant as data processorOngoing
ICO registrationregistration numberCurrent
Independent penetration teststatusdate
ISO 27001planned, or not yettarget date
ISO 42001 (AI management)planned, or not yettarget date

In writing

What we commit to contractually

These are standing terms, offered to every customer by default. They are not concessions you have to negotiate for and they do not vary by contract size.

Our roleData processor under Article 28 of the UK GDPR. You remain the controller.
Data processing agreementOffered as standard with every subscription. You do not have to ask.
No trainingWe will not use your content to train or fine-tune any model, and we impose the same term on our providers.
Breach notificationWe notify you within hours of becoming aware, so you can meet your own 72 hour duty to the ICO.
DeletionOn request or on termination, your data is deleted within how long? and we confirm it in writing.
Sub-processorsRegister maintained and published. We give how much notice? before adding one, and you may object.
Data locationProcessing in the UK. Any transfer outside it is covered by the UK IDTA or the UK Addendum to the EU SCCs.
EvidenceWe answer security questionnaires and provide evidence of our controls on request.

Questions

What review teams usually ask

Where is it hosted and processed?

Application, storage and processing sit in UK region and provider. Model inference runs with the providers listed above. If any processing happens outside the UK we say so, and it is covered by the UK IDTA or the UK Addendum to the EU SCCs.

Do you train on our documents?

No. Not us, and not our model providers. Content is used at inference time and for nothing else. It is a contractual term in your agreement rather than an account setting, so it cannot be changed without your knowledge.

Who at FireStrategy.ai can open our files?

By default, nobody. Our engineers have no standing access to production data, and our development environments contain no customer data. If you raise a support issue that requires access, it is granted to a named individual, time-limited, logged, and the log is available to you on request.

Our appointments restrict sharing client information with third parties. How does that work?

You stay in control of what is uploaded. We act as your processor under a written agreement, we do not use the information for any purpose other than delivering the service to you, and we delete it. Where an appointment or a client requires that information never leaves your infrastructure, use the self-hosted deployment, in which case we never receive it at all. We are happy to review specific confidentiality wording with you.

Is there anything you cannot delete?

Two narrow cases, and you should hear them from us rather than find them. Where content is flagged by a model provider's automated safety systems, that provider may retain it for a period set by their own policy, whatever our zero-retention arrangement says. And where we are subject to a legal hold or a statutory obligation, we must keep what the law requires. Neither is discretionary, and neither is used for any commercial purpose. Everything outside those two cases is deleted as described above.

What happens if we stop using it?

Your data is deleted within how long? of termination and we confirm it in writing. You can export your outputs before you go. There is no residual copy and nothing is kept back for any purpose.

How often is this tested?

penetration testing frequency, internal review, dependency scanning, and how findings are tracked to closure

What if something goes wrong?

We maintain an incident response process, notify affected customers within hours of becoming aware, and follow up with a written account of what happened, what was affected and what we changed. Report a concern to security contact address.

Reviewing us?

Ask for the data processing agreement, the sub-processor register, our answers to your security questionnaire, or a call with the person who built the system. Write to security contact address and we will come back within N working days.