Security & Data Privacy
Last updated: May 2026
How CAIS protects your data — encryption, isolation, authentication, AI provider boundaries, and our retention policy. Plain-English, with no surprises.
1. Data Retention
Two retention windows depending on how you use CAIS:
- Demo / anonymous uploads: Files are deleted from our processing servers shortly after the job completes. Large-file uploads via R2 are auto-purged within 48 hours via lifecycle rule.
- Registered project files: Documents you upload into a project workspace remain available while the project exists, so your TUT conversations can reference them. You can delete files, projects, or your entire account at any time from settings or the mobile app.
AI provider transient context is never persisted by us; the providers' own retention policies apply on their side only.
2. AI Providers
CAIS routes requests across multiple AI providers based on your tier:
- Free: Google Gemini 2.5 Flash
- Beta: DeepSeek V4 Pro (50K token cap)
- Pro: DeepSeek V4 Pro
- MAX: OpenAI GPT-4o (Claude or Gemini available on request)
When a request leaves CAIS to one of these providers, only the minimum context needed to deliver the requested feature is transmitted (e.g., the page being queried, not your full project).
No CAIS customer data is used to train these providers' models. CAIS does not train any models on customer documents either.
3. Encryption
- In transit: All connections use TLS 1.2+ (256-bit). HSTS is enforced on our domain.
- At rest: Database storage uses standard disk-level encryption on our VPS provider. Object storage (Cloudflare R2) is encrypted at rest by default.
- Backups: Encrypted snapshots with rotating keys.
4. Authentication
- Passwords: Hashed with bcrypt at 12 salt rounds — we never store plaintext.
- Sessions: NextAuth v5 JWT in an httpOnly secure cookie. 7-day lifetime.
- Social login: Google and Apple OAuth supported on web and mobile.
- Rate limits: 10 login attempts per 15 minutes per IP, enforced before the auth handler runs.
- CSRF: Double-submit cookie pattern on all state-changing API routes.
5. Audit Logging
All sensitive operations are logged: login, signup, password change, subscription change, admin action, file deletion, account deletion. Logs include user ID, action, timestamp, and IP (truncated for privacy). Logs are retained for incident review and never exposed to other users.
Customer access to your own audit trail is on the roadmap (MAX tier).
6. Job Isolation
Each AI processing job runs inside its own Docker container with no shared filesystem with other jobs. No cross-tenant data leakage by design — jobs cannot see each other's files, environment, or memory.
Worker queues are namespaced per user; one user's quota or rate-limit failures cannot starve other users' jobs.
7. Business Security Roadmap
Available through a Business Inquiry (Contact Sales):
- Single sign-on (SAML / OIDC)
- SCIM user provisioning
- Customer-managed encryption keys (BYOK)
- VPC peering / private network access
- SOC 2 Type II report (in progress)
- Data residency commitments (KSA, EU, US options)
Talk to us if any of these would unlock a deal.
8. Security Contact
For security issues, vulnerability reports, or privacy questions:
- Email: [email protected]
- Vulnerability reports: please use the same email, subject prefix "[SECURITY]".
We respond to vulnerability reports within 48 business hours. Please do not publicly disclose issues before we have a chance to investigate.