Security posture

    Zero-trust from the first line of code.

    Built from the ground up with a zero-trust security model. Your data is protected at every layer — and the strongest layer is that the confidential value never reaches the AI at all.

    Data residency, answered differently

    We don't keep confidential data in Canada. We make sure there isn't any confidential data to keep.

    Every other “compliant AI” answers the residency question with a location — a region you select and a policy you trust. Untraceable answers it upstream: the real value is cloaked on your computer before any model sees it, so the thing residency laws exist to protect never enters the pipeline.

    01

    Nothing confidential to localize

    The AI only ever receives cloaks. Real values are replaced on your own computer before anything is transmitted, so there is no confidential data in the payload to keep in one country or another. Residency stops being a promise about a database and becomes a property of the architecture.

    02

    A PIA we aren't required to file — filed anyway

    Because no confidential value is ever disclosed to the AI, the privacy assessments that assume disclosure don't strictly attach to that step. We complete a Privacy Impact Assessment regardless — the standard we're held to is the one we choose, not the minimum the law leaves us.

    03

    We enforce what the providers won't commit to

    Frontier providers may have Canadian capacity, but selecting a region and being held to it are not the same thing — few will contractually guarantee your data never leaves it. Untraceable routes through residency-proof APIs with a fail-closed check and no silent fallback: if a region can't be honored, the request stops. We enforce what the providers won't commit to.

    Selecting a region and being held to it are not the same thing. We enforce what the providers won't commit to.

    The architecture is the compliance.

    Confidentiality law — PIPEDA, Quebec Law 25, the disclosure clauses in an NDA — is built around a moment of disclosure: a confidential value leaving your control and reaching someone else. Untraceable removes that moment. The AI never receives the value, so the obligations that hinge on disclosure don't even attach to the AI step in the first place. The safest way to comply with a rule about sharing data is to never share the data.

    We don't stop there. We still run the assessments, still honor residency, still keep an audit trail of every cloak and every submission — not because the law forces us to at that step, but because regulated clients deserve to see the belt and the braces. Doing the work you're not strictly required to do is the whole posture.

    Zero-trust architecture

    Every route authenticated via JWT. Least privilege on Key Vault, database, and Graph. No exceptions.

    No documents to AI

    AI models receive only cloaked data — never your files, never your raw text. Documents stay in your vault.

    Four gates before transmission

    A cloak-coverage test, a sentinel that catches stray numerical and alphanumeric values, a breach test in which a separate model tries to reconstruct the real values, and a compulsory human certification. Recover even one value and the submission is rejected — zero tolerance, not a threshold.

    Never used for training

    Contractual guarantee: your inputs are excluded from AI model training. Period.

    Guaranteed deletion

    No memory retention. Session data is cleared immediately after processing. Nothing persists.

    Regional data residencyEU — coming soon

    Choose your server location: US East Coast or Canada — enforced, not just selected. West Europe (Netherlands) is planned and not yet available.

    Regulatory alignedSOC 2 Type I — late 2026

    Privacy-by-design tools aligned with HIPAA, PIPEDA and GDPR principles. This is an alignment claim, not a certification: no third-party attestation is held today.

    Why a no-training promise isn’t the same as safety

    Reviewing generative AI for health technology assessment, an ISPOR Working Group notes that these models can memorise the data they were trained on and reproduce it later, and advises against putting protected health information into them at all — because absolute de-identification is not attainable and re-identification risk stays non-zero (Fleurence et al., Value in Health 2025;28(2):175–183). Contractual no-training and retention terms are worth having, and we hold them. But they are promises about what a third party will do with your data once it has it. Text that never leaves your computer cannot be memorised, cannot be reproduced, and needs no promise at all.

    How “on your computer” works

    All document processing and cloaking runs client-side, in your browser — no installation, no plugin, and no file ever uploaded to our servers. Only cloaked values are transmitted to the AI models. Your files and real data remain local to your device for the entire workflow.

    Regional Security & Compliance

    Where cloaks, audit records and compute do live, they stay put. Each region has its own isolated compute and storage — enforced. AI inference runs in-region where the provider offers it (e.g. Gemini in Canada); models without an in-region endpoint (Claude, GPT) run in a US region on cloaked text, disclosed up front — never a silent cross-region switch.

    🇨🇦

    Canada

    Compliance
    • Quebec Law 25 (privacy)
    • PIPEDA-aligned architecture
    Infrastructure
    • Compute & storage in Toronto
    • AI inference: Canada-resident for Gemini; Claude & GPT run in a US region on cloaked text (disclosed)
    • Backup in Quebec City
    🇺🇸

    United States

    Compliance
    • HIPAA-aligned architecture
    • SOC 2 Type INot held — initiating late 2026
    • SOC 2 Type IINot held — planned H1 2027
    Infrastructure
    • All storage, compute, and AI inference in East US (Virginia)
    🇪🇺

    EuropeComing soon

    Compliance
    • GDPR enabler — privacy-by-design architecture
    Infrastructure
    • Planned: all storage, compute and AI inference in the Netherlands — not yet live

    Trust center

    The documentation a security review asks for.

    Subprocessors, residency, retention, encryption, key custody and certification status — stated plainly. Where a row is not yet answerable it says so rather than inferring an answer.

    Subprocessors

    Third parties that receive data in the course of delivering the service. AI providers receive cloaked text only — never a confidential value.

    AI model providers
    OpenAI, Anthropic, Google, Mistral and Meta. Premium tier: GPT 5.6 Sol & Terra, GPT 5.4, Fable 5, Claude Opus 4.8, Claude Sonnet 5, Gemini 3.1 Pro. Standard tier: GPT 5.6 Luna, GPT 5.4-mini, Claude Haiku 4.5, Gemini 3.5 Flash, Mistral Large, Llama 4.
    What they receive
    Cloaked text only. Real values are replaced on the customer's own device before any call is made.
    Training on inputs
    Contractually excluded across all model providers.
    Cloud infrastructure
    Microsoft Azure only — compute, storage, gateway and key management. Everything else in the workflow runs client-side in the customer's own Microsoft 365 tenant. There are no separate analytics, email or support subprocessors.
    Customer document storage
    The customer's own Microsoft 365 tenant. Documents are not copied into Untraceable's infrastructure.

    Residency by region

    Where cloaks, audit records and compute live. AI inference runs in-region where the provider offers an in-region endpoint; where it does not, the model runs in a US region on cloaked text, disclosed up front — never a silent cross-region switch.

    Canada
    Compute and storage in Toronto; backup in Quebec City. AI inference Canada-resident for Gemini; Claude and GPT run in a US region on cloaked text (disclosed).
    United States
    All storage, compute and AI inference in East US (Virginia).
    EuropeComing soon
    Planned: all storage, compute and AI inference in the Netherlands. Not yet available to select.
    Cross-region fallback
    None. The residency check is fail-closed: if a region cannot be honored, the request stops rather than rerouting.

    Data retention

    Never retained
    Confidential values, source documents and per-document keys. None of these reach Untraceable's infrastructure at any point.
    Retained — cloak audit trail
    Cloak labels, run identifiers, model and timestamp for each submission. No real value appears in the record. Retained for 6 years per regulated-industry standards, or for a customer-defined period.
    Retained — conversational tools
    Cloaked prompts and cloaked responses for VaultChat and VaultDelphi, so a run can be reopened and audited. Retained for 1 year, or for a customer-defined period.
    Session data
    Cleared immediately after processing; no memory retention across sessions.
    Deletion on request
    On written request. Cloak-level records held by Untraceable are deleted within 48 hours and deletion is confirmed; documents and keys live in the customer's own tenant and are theirs to delete.

    Encryption & key custody

    In transit
    TLS 1.2 minimum across the website and both API gateways (Canada and United States); TLS 1.0 and 1.1 handshakes are refused. Connections negotiate TLS 1.3 with AES-256-GCM by default. Legacy TLS 1.2 suites (static-RSA key exchange, and CBC with SHA-1) remain enabled on the platform for backward compatibility and are not disabled at our tier; in practice no supported client selects them, since Microsoft 365 sign-in already requires modern suites. Verified by handshake test 2026-08-23.
    HTTPS and HSTS
    Web properties are served over HTTPS only and send Strict-Transport-Security with a two-year max-age, includeSubDomains and preload. The API gateways do not send HSTS; they are not browser-navigated origins.
    At rest
    AES-256 with Microsoft platform-managed keys, on both the database and blob storage. Customer-managed keys for the platform store are not offered today. Note this is separate from cloak keys, which are always per-document and held in the customer's own tenant. Verified 2026-08-24.
    Key custody
    Cloak keys are per-document and held in the customer's own Microsoft 365 tenant. Untraceable never holds a key and cannot decloak a document.
    Platform secrets
    Azure Key Vault under RBAC, least privilege on database, Key Vault and Graph.

    Controls

    Breach-test gate
    Before transmission, a separate model is given the cloaked text and told to reconstruct the real values. If it recovers even one, the submission is rejected. Zero tolerance, not a threshold.
    Cloak-coverage test
    Confirms the model receives exactly what the user reviewed — nothing added, nothing uncloaked.
    Closing sentinel
    A final screening pass that catches stray numerical and alphanumeric values the user may have missed.
    Human certification
    Compulsory. The automated gates cannot certify a run on their own — a person reviews and certifies before the submission is released.
    Authentication
    Every route authenticated; the health check only is open. Tenant isolation is enforced in the database at the row level.
    Audit trail
    Every cloak and every AI submission recorded, exportable for a given deliverable, referencing cloak labels and run IDs only.

    Certifications & attestations

    No third-party attestation is held today. The rows below state status, not aspiration.

    SOC 2 Type IInitiating late 2026
    Not held. To be initiated in late 2026.
    SOC 2 Type IIPlanned H1 2027
    Not held. Planned for H1 2027.
    ISO 42001Planned H1 2027
    Not held. Planned for H1 2027.
    HIPAA
    Architecture aligned to HIPAA principles.
    PIPEDA / Quebec Law 25
    Architecture aligned; a Privacy Impact Assessment is completed voluntarily.
    GDPREU region coming soon
    Privacy-by-design architecture. EU residency not yet available.
    Microsoft AI Cloud Partner Program
    Member.
    Penetration testingPlanned Q4 2026 / Q1 2027
    No third-party penetration test has been completed yet. Testing is planned for Q4 2026 and Q1 2027.

    Need something not listed here? Ask us directly — or read the Untraceable Protocol.