Security

How Rectifies handles your data.

Data we collectCustomer prompts, customer brand identifiers, crawled public web content (per /crawler)
Data we don't collectCustomer-identifying personal data, paywalled content, content blocked by robots.txt
Where data is storedHetzner (EU — Falkenstein), Cloudflare R2 (EU). Postgres 16 with pgcrypto for sensitive fields
EncryptionTLS 1.3 in transit, AES-256 at rest
Access controlsTailscale-only admin SSH, no public SSH. Two-factor auth on all human accounts
BackupsHetzner daily 7-day retention + weekly pg_dump to Cloudflare R2
ComplianceGDPR (UK + EU), DPA available on request. Not yet SOC 2
CrawlerWe operate one crawler, documented at /crawler
Security disclosuresecurity@rectifies.io

Subprocessors

SubprocessorPurposeLocation
HetznerInfrastructure, databaseEU (Germany)
CloudflareR2 storage, CDNEU
OpenAI APIEngine probing (ChatGPT)US
Anthropic APIEngine probing (Claude)US
Perplexity APIEngine probingUS
Google AIEngine probing (Gemini)US
Hugging FacePublic dataset hostingUS
GitHubCode hostingUS