This page describes the technical measures implemented or planned for the private pilot of Expedientia. It does not constitute a security certification. Before real case files are uploaded, the technical testing, the risk assessment and the contractual documentation indicated in the Privacy Policy must be completed.
The service’s D1 database and R2 storage are configured with EU storage jurisdiction in Cloudflare. The content necessary for extraction, analysis or transcription is transmitted to OpenAI via API and may be processed outside the EEA. The data-processing agreement, transfer safeguards and impact assessment must be finalized before real data is used; for this reason we do not claim the service is “EU-only”.
File format and size validation should not be interpreted as a complete antivirus scan. No active malware-detection guarantee is declared for the pilot.
Two-factor authentication (2FA) is available and recommended for any pilot account. It is not presented as mandatory while its enforcement has not been verified end to end.
Cloudflare and OpenAI take part in the technical flow described in the Privacy Policy. Resend and Stripe only come into play if transactional email or payments are enabled. Anthropic is not used in the MVP’s documented flow. Retention periods held by the AI provider, security logs and infrastructure copies depend on the configuration and contracts in force and must be set out in the final documentation.
This version does not publish an absolute promise of “zero retention” or that “data never trains models” until those conditions are verified and documented for the account and contract actually in use.
The application’s purge removes the originals, extracted text and product records linked to the case file. Any residual periods held by providers, operational logs and infrastructure copies must be defined in the final policy and contracts; the request is therefore not presented as instant deletion of every possible copy.
If you believe you have found a vulnerability in Expedientia, report it privately to info@dathent.com. The formal incident-response procedure and notification obligations will be specified in the contractual documentation before the pilot with real data.