Security & Trust

Security is a first-class product surface,
not a compliance afterthought.

Your P&IDs, isometrics, HAZOP registers and NOC-tier deliverables are among the most sensitive documents in your business. Here is exactly what we do with them, and what we never do.

Procurement-ready answers

The six questions your security team will ask.

Answered inline, no NDA required to read.

Do you train models on our documents?

No. Never. Customer documents are processed for the review that generated them and are never used to train, fine-tune, or retrain any model. This is contractual, not aspirational.

Where does the data live?

EU-region hosting by default (Frankfurt for compute, London for storage). UK, EU, and UAE data-residency options available on Team and Enterprise tiers. Regional-only pinning available on request.

What happens to our IP?

It remains yours. All outputs — findings, comment registers, redlines — are your intellectual property. We assert no rights over inputs or outputs beyond the license needed to deliver the review.

How is data isolated between customers?

Per-tenant logical isolation on all storage, per-tenant encryption keys on Enterprise. No cross-customer query paths. Every document access is logged with actor, timestamp, and purpose.

Where does the AI stop and the engineer start?

The AI produces candidate findings. A Chartered Engineer triages severity, discards false positives, and signs the final register. You are never shown machine output without human review on supervised tiers.

How do we get our data out?

One click. Full export of all documents, findings, and comment registers as PDF, CSV, and native formats. Deletion on request within 30 days, with written confirmation and destruction attestation.

Security posture

Five pillars, no hand-waving.

Encryption everywhere.

Data is encrypted at rest and in transit. No exceptions, no legacy paths.

  • AES-256 at rest across storage and backups
  • TLS 1.3 in transit, HSTS enforced
  • Per-tenant encryption keys on Enterprise
  • Encrypted backups with 90-day retention

Regional hosting.

Your engineering data does not leave your region.

  • EU-default (Frankfurt compute, London storage)
  • UK, EU, UAE data-residency options
  • Pinned regions available on request
  • No cross-region replication by default

Access is auditable.

Every document access is logged with actor, timestamp, and purpose.

  • Full audit trail for every review action
  • SSO/SAML available on Enterprise
  • Role-based access with least privilege
  • Named Security Point of Contact on Enterprise

Zero training on your data.

Your documents feed reviews, never model weights.

  • Contractual guarantee, not marketing language
  • No fine-tuning on customer documents
  • No prompt-tuning on customer content
  • Prompt-inspection logs available on request

IP retention.

Everything you send in and everything we send back is yours.

  • Customer owns all inputs and outputs
  • Minimum license needed to deliver the review
  • No downstream use of findings or registers
  • Deletion on request with destruction attestation

Incident response.

If something goes wrong, you hear from us fast and in writing.

  • 4-hour acknowledgement window
  • 24-hour written response commitment
  • Named Security POC on Enterprise
  • Pre-agreed breach notification thresholds
Compliance roadmap

SOC 2 timeline.

We are transparent about where we are in the compliance journey. Nothing below is claimed as achieved until it is auditor-signed.

Q4 2026

Formal information-security policy set adopted.

Written policies covering access control, encryption, incident response, vendor management, business continuity, and secure development. Board-signed.

Q1 2027

SOC 2 Type I audit — targeted.

Point-in-time attestation from a reputable audit firm. Type I confirms controls are designed correctly.

Q3 2027

SOC 2 Type II audit — targeted.

6-month observation window. Type II confirms controls operate effectively over time. This is the badge Enterprise procurement teams actually accept.

Q4 2027

ISO 27001 — targeted.

For customers where SOC 2 is not enough (typically European majors and NOC-tier). Roadmap only; timing subject to demand signal.

Incident response.

If you believe a SpecSense-processed document has been exposed or misused, contact security@specsense.ai. We commit to acknowledgement within 4 business hours and a written response within 24 hours.

Enterprise customers receive named Security Point of Contact, documented SLAs, and pre-agreed breach notification thresholds.

Ready to run a supervised pilot?

48 hours. Chartered-engineer sign-off. Data isolated per pilot.