Security
These are the questions we are asked most often about how your documents are handled. Every figure below is verified against the running system. Where our answer is imperfect, we have said so rather than left it out. Full technical detail — data flow, sub-processors, encryption, and access control — is in our Technical Security & Data Protection Brief, available on request.
The title commitment itself never goes to Anthropic. It is sent to Microsoft's Document Intelligence service for text extraction, and Microsoft deletes it within 24 hours. What is sent to Claude is the extracted text — in full, but as text only. No PDF, no images, no signatures. The same is true of the flood determination and zoning report. (The ALTA survey is the exception, and is covered in the next question.)
That text is not recoverable. It is sent inline with the analysis request, and the messages API it uses stores no object you or anyone else can fetch back — there is no request identifier and no endpoint that returns a past request. Your documents are never used to train AI models, so nothing from them can surface in anyone else's session.
Anthropic retains the request and response in an internal safety log for up to 30 days and then deletes them. No one reads that log unless automated safety systems flag content.
Yes — the survey file itself is sent. A survey is a drawing, and the only way to analyze it is to look at it. This is the one document whose file leaves our systems, and it goes in full: every page, including the surveyor's seal and signature block. Unlike the text sent for the other documents, it is stored at the provider as a file with an identifier for the duration of the analysis.
It exists there for the length of the analysis run — normally two or three minutes, longer if a step has to be retried — and we delete it as soon as the run finishes. A scheduled daily sweep removes anything left behind by a run that failed part-way through, so a failure cannot leave your survey sitting at the provider.
The file is never public, never accessible to another customer, and never used for training.
Ninety days from the date the review is created. At that point the uploaded PDFs, the extracted text, the findings, and the report are all permanently deleted. This is a hard delete, not an archive. We email you 14 days beforehand; if that email cannot be delivered, the review is held through a further grace period rather than removed silently. You can extend by another 90 days from your dashboard if the deal is still live, up to a one-year limit.
You do not have to wait for any of that. Your dashboard carries a delete control on each review, and using it removes the files and records immediately. Ninety days is a ceiling, not a commitment. If a client asks you to destroy their materials, you can satisfy that obligation yourself the same day, without contacting us or waiting on our retention schedule. Reviews you start but never run are removed automatically within seven days.
Two records outlive the review by design, and neither contains document content: a one-way hash of the email address used to claim a free review, kept to prevent abuse, and — if you email a copy of a report to a third party — the recipient's address and the subject line, kept as a record of the disclosure. Both are described in our Privacy Policy, and the recipient record can be erased on request.
Nobody can open your uploaded PDFs through the application. There is no screen and no endpoint that serves an uploaded document file to a member of our staff.
Our administrative console displays review metadata only — status, date, entity name, score, review standard, the model used, and payment status. It cannot open a document, show extracted text, or show findings.
We will be straightforward about the limit of that, because it is the kind of thing worth knowing before you ask: there is a separate internal endpoint, restricted to administrators who hold an administrator account and have completed multi-factor authentication in that session, which returns a review's extracted text and findings. It exists for support and debugging. It does not return the uploaded PDFs themselves. In practice that means a small number of named staff can read the text of your title commitment and the findings we generated from it, in the same way they could by querying the database directly.
Beyond that, the same small number of named engineering staff have direct access to the underlying database and file storage for incident response, protected by multi-factor authentication on those platform accounts. That access is not used for routine support.
Two independent layers. Row-level security is enforced in the database itself, scoped to your account — if a request arrived carrying another customer's record identifier, the database returns nothing. The application is not what enforces this.
Separately, every API route that touches your data re-verifies ownership before acting, and returns “not found” rather than “access denied,” so record identifiers cannot be probed for existence. Documents are stored in a private bucket under a path keyed to your account, with no public URLs.
We verified this against our production environment: using the public client key, every customer table returned zero rows and the document bucket refused access outright.
No. We do not hold SOC 2 Type II or ISO 27001, and we would rather tell you directly than have you discover it in diligence.
Our providers do. Anthropic, the AI provider, holds SOC 2 Type II, ISO 27001:2022, and ISO/IEC 42001:2023 — the management-system standard specific to artificial intelligence. Microsoft Azure, Supabase, and Vercel hold SOC 2 Type II. Payments are processed by a PCI DSS Level 1 provider, so no card data enters our environment at all.
We can share current reports for each of these under NDA, along with the results of our own internal security review covering access control, tenant isolation, and the processing pipeline. If SOC 2 certification is a requirement for your organization, tell us — and tell us your timeline.
We cannot answer that for you — it depends on your specific agreements, and it is your counsel's call. What we can do is tell you exactly what we are, so you can check us against them.
Most confidentiality agreements in commercial real estate permit disclosure to service providers and professional advisors, provided it is on a need-to-know basis, the provider is bound by obligations at least as protective as the agreement itself, and you remain responsible for the provider's compliance. Need-to-know is enforced here in software rather than policy. Your documents are not used for training, not sold, and not disclosed to anyone outside a short list of named providers, each bound by a written data processing agreement. We will sign your NDA and your data processing agreement directly.
Four things are worth checking against your own agreements: whether they require notice or consent before a sub-processor is engaged; whether they impose geographic restrictions — all processing of your documents takes place in the United States, and the only sub-processor located outside it is the form tool behind our optional feedback prompt, which is in the European Union and receives no document content; whether they require vendors to hold certified controls; and what is actually being uploaded, since deal documents alone are sufficient for the review to work.
One clause deserves particular attention. Some newer agreements prohibit submitting confidential material to AI systems outright. If yours contains that language, we cannot engineer around it — analysis by a language model is the product. We would rather raise that now than have you discover it after signing.
Our Privacy Policy covers data categories, sub-processors, your rights, and data subject access requests. Our Terms of Service cover retention and account deletion contractually. For anything else — including a copy of the Technical Security & Data Protection Brief, or to send us your NDA or vendor security addendum — write to information@titleandsurveyreview.com.