πŸ”’
Security & Trust Center

Enterprise-grade protection for your retirement plan data

βœ“

All Systems Secure

Your data is protected with enterprise-grade security and never used for AI training.

πŸ”Œ API-First Architecture β€” Not a Chatbot

This application connects to enterprise AI APIs, not consumer chatbots like ChatGPT.com or Claude.ai. Your data is never used for training, never stored in shared conversation logs, and never reviewed by humans.

How Your Data is Protected
πŸ“„
Your Data
β†’
πŸ”
TLS 1.3
β†’
☁️
Cloudflare
β†’
πŸ€–
AI Analysis
β†’
πŸ—‘οΈ
Auto-Delete
Core Security Features
🚫
Zero Training Guarantee
No AI provider uses your inputs or outputs to train models. Contractually guaranteed.
πŸ”
End-to-End Encryption
AES-256 at rest, TLS 1.3 in transit. Encrypted at every stage.
⏱️
Minimal Retention
AI providers retain data 7-30 days max, then permanently delete.
πŸ‘οΈβ€πŸ—¨οΈ
No Human Review
Unlike consumer chatbots, your conversations are never reviewed by humans.
Compliance Certifications
πŸ†
SOC 2Type II Certified
🌐
ISO 27001Information Security
πŸ›οΈ
FINRASEC 17a-4
πŸ₯
HIPAABAA Available
πŸ‡ͺπŸ‡Ί
GDPRCompliant
πŸ‡ΊπŸ‡Έ
CCPACompliant
πŸ’‘ Tip: See the DOL Compliance tab for detailed responses to all 12 DOL Cybersecurity Best Practices requirements.

We use enterprise API tiers from the leading AI providers. Your data is never used for training and has strict retention limits.

Consumer Chatbot vs. Enterprise API
Security AspectConsumer ChatbotsEnterprise API (What We Use)
Training on your data❌ May train on conversationsβœ“ NEVER trains on your data
Data retention❌ Stored indefinitelyβœ“ 7-30 days max, then deleted
Human review❌ May review for qualityβœ“ No human review of content
Privacy policies❌ Consumer privacy termsβœ“ Enterprise DPA / BAA available
Compliance❌ Limited certificationsβœ“ SOC 2, ISO 27001, HIPAA-ready
Our AI Providers

Anthropic Claude

Claude Sonnet 4 API
SOC 2 Type IIISO 27001HIPAA
  • Zero Data Retention (ZDR) option
  • No training on API data β€” ever
  • 30-day max retention

OpenAI GPT

GPT-4o / GPT-4 API
SOC 2 Type IIISO 27001ISO 27701
  • No training on API data by default
  • Data Processing Addendum (DPA)
  • Enterprise Key Management

Google Gemini

Gemini 2.0 Flash API
SOC 1/2/3ISO 27001FedRAMP High
  • No training on customer data
  • ISO 42001 AI Management
  • HIPAA BAA available
Document Storage

Enterprise-Grade Document Storage

When documents are stored, they reside in Box.com's secure cloud with automatic retention policies and encryption.

FINRA SEC 17a-4SOC 1/2/3ISO 27001HIPAAFedRAMP
πŸ”„ How Your Data Flows

Understanding exactly what data is sent where gives you confidence in our security architecture.

Secure Processing Pipeline
πŸ“„
Your Document
Stays on device
β†’
πŸ–₯️
Browser
Text extraction
πŸ”’β†’
☁️
Cloudflare
Secure proxy
πŸ”’β†’
πŸ€–
AI Analysis
No retention
β†’
πŸ“Š
Results
To your browser
πŸ“¦ What Data Is Sent
βœ…
Text Content Only
Only extracted text is sent to AI providers. Original PDF/Excel files are never uploaded to external servers.
πŸ”
Encrypted in Transit
All data uses TLS 1.3 encryption between your browser and our servers, and between our servers and AI providers.
πŸ›‘οΈ
API Keys Protected
Your API keys are stored securely in Cloudflare Workers. They never touch your browser or frontend code.
⚠️ Important: Original files are NOT uploaded. Only extracted text content is sent for analysis.
πŸ“ Document Storage Security

Enterprise-Grade Document Storage

When documents are stored (optional), they reside in Box.com's secure cloud with automatic retention policies, audit trails, and encryption at rest.

FINRA SOC 1/2/3 ISO 27001 HIPAA FedRAMP
πŸ”
AES-256 Encryption
All stored documents are encrypted at rest using AES-256 encryption with Box-managed keys.
πŸ“‹
Full Audit Trail
Every access, modification, and download is logged with timestamps and user identification.
πŸ›οΈ
FINRA SEC 17a-4
Compliant with financial services record-keeping requirements for broker-dealers and RIAs.
πŸ’‘ Storage is Optional
Many (k) Suite applications process data entirely in your browser without storing anything externally. When storage is needed (e.g., for prep packages or audit trails), Box.com provides enterprise-grade security. You control what gets stored.
βš–οΈ Regulatory Compliance
βš–οΈ
ERISA
Designed for fiduciary compliance. Full audit trails document prudent processes. No PII leaves your control without explicit action.
πŸ›οΈ
FINRA / SEC
Box storage meets SEC 17a-4 requirements for record retention. Automated retention policies and legal holds supported.
πŸ“‹
DOL Cybersecurity
Aligned with DOL's cybersecurity guidance for plan fiduciaries. Encryption, access controls, and incident response documented.
πŸ‡ͺπŸ‡Ί
GDPR
Data minimization by design. No unnecessary retention. Clear data processing purposes. DPA available from AI providers.
βœ… TPA Compliance Checklist

πŸ” Security Controls Implemented

βœ“ No PII stored on external AI servers
βœ“ Encrypted data transmission (TLS 1.3)
βœ“ No AI training on plan data
βœ“ SOC 2 Type II certified providers
βœ“ Audit logging for all transactions
βœ“ Role-based access controls
πŸ“„ Documentation: For fiduciary due diligence, SOC 2 reports are available under NDA from each provider's trust center.
❓ Frequently Asked Questions

No. We use enterprise API tiers. All providers explicitly state that API data is NOT used to train models. Contractually guaranteed.

AI providers retain data for 7-30 days for abuse monitoring, then permanently delete. Anthropic offers Zero Data Retention.

No. Enterprise API data is NOT subject to human review. Only automated abuse detection processes the data.

PII is handled with extreme care. Census files are processed locally when possible. We never store SSNs. All PII in transit uses TLS 1.3.

Documents are processed locally in your browser. Only extracted text is sent β€” original files never leave your device.

Our infrastructure relies on SOC 2 Type II certified providers: Cloudflare, Anthropic, OpenAI, Google, and Box.com all maintain current certifications.

Anthropic: SOC 2 Type II, ISO 27001, HIPAA
OpenAI: SOC 2 Type II, ISO 27001/27017/27018/27701
Google: SOC 1/2/3, ISO 27001, FedRAMP High, HIPAA
Box: SOC 1/2/3, ISO 27001, FINRA SEC 17a-4, FedRAMP