Trust & security

Built for regulated document workflows

DataStruct AI is designed for teams whose outputs need to defend themselves: to auditors, regulators, courts, and internal review. Here is how the platform supports that.

Honest about status. Items are labelled Available, In progress, or Planned. We will not claim a certification we do not hold. SOC 2 audit timeline is shared during procurement.

Access control

Who can do what, scoped to a workspace, with full traceability.

Workspace-based RBAC

Available

28 granular permissions across four roles (Owner, Admin, Member, Viewer). Every workspace endpoint is permission-gated.

Multi-tenant isolation

Available

Organisation → Workspace → Membership hierarchy with strict tenant boundaries enforced at the data and API layer.

API key management

Available

Hashed, prefix-indexed API keys with optional expiry and per-key usage tracking. Revocation is immediate.

SSO / OIDC

Available

Google OAuth and generic OIDC support for enterprise single sign-on. SAML available on Enterprise on request.

Session controls

Available

Short-lived JWT access tokens with refresh; sign-out everywhere from the user settings page.

Evidence and auditability

Every AI output is grounded in source material, validated, and reviewable.

Paragraph-level citations

Available

Every Q&A answer cites the exact source paragraph. Reviewers can click through to verify.

Citation validation

Available

Generated citations are checked against the retrieval set; fabricated references are flagged before reaching the user.

Verification pass on AI outputs

Available

A second model pass evaluates each claim against the cited evidence and flags unsupported claims in system logs for operator review.

Confidence-based abstention

Available

When confidence falls below threshold, the system says "insufficient evidence" rather than guessing.

Review queues

Available

Low-confidence extraction results and low-confidence answers auto-route to a human review queue. Approve, reject, or edit; every decision is recorded.

Full audit log

Available

Sensitive actions (uploads, AI calls, review decisions, rule overrides, configuration changes) are logged with actor, target, and before/after values.

Data protection

Customer data is encrypted in transit and at rest, isolated per tenant, and exportable on request.

Encryption in transit

Available

TLS 1.2+ for all API and frontend traffic. HSTS enforced.

Encryption at rest

Available

AES-256 server-side encryption on document object storage. Database disk encryption inherited from the managed Postgres provider.

S3-compatible object storage

Available

Documents stored in customer-controllable S3 buckets when self-hosting; managed buckets when on multi-tenant SaaS.

Soft-delete patterns

Available

Most resources use soft-delete with timestamps so accidental deletes are recoverable for the retention window.

Data export and erasure workflows

Available

GDPR Article 15 (export) and Article 17 (erasure) self-serve from the user settings page; bulk export available via API on Business and above.

Configurable retention

Planned

Per-resource retention windows configurable per workspace.

AI processing and provider options

How AI calls are routed today and what is planned for organisations with stricter procurement or data-handling requirements.

Managed AI by default

Available

DataStruct AI runs on managed AI infrastructure so customers can start quickly. Usage is governed by fair-use limits to protect performance and cost predictability.

Per-organisation usage limits

Available

Each organisation has daily and monthly AI cost caps with hard-stop at the limit and an audit log warning at the warning threshold. Limits are set per contract.

AI call audit trail

Available

Every AI provider call (Q&A, verification, search reranking, query and document embeddings, extraction and claim extraction) is recorded with provider, model, token counts, estimated cost, and credential source.

No foundation-model training on customer data

Available

Customer documents are not used to train DataStruct AI foundation models. Where third-party AI providers process content, retention and handling depend on the selected provider, account configuration, and contracted controls.

Customer-managed provider keys

Planned

For organisations that require direct control over provider billing and data-handling settings, customer-managed AI provider keys are on the enterprise roadmap. Contact sales to discuss timelines.

Azure OpenAI / provider retention controls

Planned

Azure OpenAI routing and provider-level retention controls (including Zero Data Retention where eligible) are on the enterprise roadmap for procurement-driven deployments.

Redaction before LLM processing

Planned

Optional redaction of common PII (emails, phone numbers, identifiers) before evidence chunks are sent to the AI provider. On the roadmap.

Enterprise operations

Operational hardening so DataStruct AI fits into existing engineering and security workflows.

Webhooks with HMAC signatures

Available

Document and workflow events fire to your endpoint with HMAC-SHA256 signatures, exponential retry, and auto-disable after repeated failures.

Rate limits

Available

Per-IP request rate limits on API endpoints, plus per-organisation daily and monthly AI cost caps.

AI cost governance

Available

Daily AI cost ceiling with warning threshold and audit logging. Budget alerts surface in the operator console.

Health checks

Available

/health and /health/ready endpoints expose database and Redis connectivity for load balancer probes.

Structured logging

Available

JSON-structured logs with request IDs for tracing. Sentry integration for error monitoring.

Feature availability flags

Available

Public /admin/ops/info endpoint exposes which subsystems are configured (AI, email, billing, storage) so banners can warn users instead of letting them hit confusing errors.

Compliance posture

DataStruct AI is built around the controls that regulated document teams actually need.

GDPR-aligned data subject rights workflows

Available

Self-serve Article 15 export and Article 17 erasure endpoints. Right-to-rectification supported via account profile updates and audit-logged data corrections.

DPA template

Available

Standard Data Processing Addendum available on request and shared during procurement.

Standard Contractual Clauses (SCCs)

Available

EU SCCs for international transfers available on Enterprise engagements.

Sub-processor list

Available

Sub-processor list shared during procurement. Notification of material changes via email.

SOC 2 readiness roadmap

In progress

SOC 2-aligned controls in place across access, audit, encryption, and incident response. Type I report planned; Type II audit timeline shared during procurement.

Incident response plan

Available

Documented incident response procedure with severity classification, communication SLAs, and post-incident reviews.

Procurement support

How we help your security and procurement teams approve DataStruct AI faster.

Security questionnaire support

Available

Standard questionnaires (SIG, CAIQ, custom forms) returned within 5 business days during active procurement.

Architecture and deployment review

Available

Working session with your security team to walk through data flows, access model, encryption, and incident response.

Optional data residency

Available

EU data residency available on Enterprise engagements; additional regions on request.

Optional dedicated environment

Available

Single-tenant deployment available on Enterprise. Pricing reflects the dedicated infrastructure.

Reference customers

In progress

On-request introductions to existing customers (subject to mutual NDA).

Bring your security team

Book a security working session and we will walk through data flows, RBAC, audit, encryption, and incident response with your team.