Data processing

Pilot Data Processing & Security Summary

A diligence-oriented summary of how the current private pilot handles customer workspace data.

Not an executed DPA. This is a technical/data-processing summary for pilot diligence. A signed DPA, any required international-transfer mechanism, the contracting entity and provider-specific subprocessor terms remain commercial-launch requirements.

Role by data category

For account, authentication, service-security and operational data, Sefixa determines processing needed to operate the service. For customer workspace documents and response content, the intended model is that Sefixa processes content to provide the service on the workspace customer's instructions. The exact controller/data-fiduciary/processor allocation must be reflected in the final customer agreement for the applicable jurisdiction.

Technical and organisational measures

Access controlAuthenticated workspace membership and role checks; tenant-scoped server queries; RLS as an additional database boundary.
StoragePrivate object storage for retained originals; authenticated no-store download paths.
Session securityRotating HttpOnly session cookies and provider-side token validation.
Abuse protectionPersistent rate limiting, request IDs, security headers and production condition monitoring.
Human controlUnsupported claims fail closed and human approval remains explicit before final response use.

Current infrastructure snapshot

The current hosted pilot uses Supabase for data/auth/private storage and Vercel for the application runtime. The Supabase project is presently configured in ap-northeast-2; recent production Vercel deployments execute in iad1. This is an operational snapshot, not a permanent residency commitment. Any paid-customer residency promise must be separately agreed and technically enforced.

Subprocessors and AI

Supabase and Vercel are core hosted-pilot infrastructure providers. An external AI drafting provider is conditional, not assumed. If enabled, the provider/model should be identified to the customer before confidential processing and its data-use, retention and international-transfer terms reviewed.

Return and deletion

Owners can obtain structured workspace export plus authenticated original-file downloads. Project/evidence deletion is implemented in-product. Full workspace application-data deletion has been exercised on disposable production data; deletion of a workspace containing non-empty private Storage and final Auth-identity removal remain procedures that must be fully exercised before they are represented as a one-step automated capability.