Stijn AI
Security

What happens to your data, stated plainly

Sending your business data to a third party to be processed by a model is a real risk. Here is exactly what we do about it, and what we do not claim.

We do not train on your data

Your inputs and outputs are never used to train any model, ours or a provider's. This is not a toggle buried in settings that you have to find and switch off. It is the only mode we operate in.

Retention is 30 days, or zero

Run inputs and outputs are kept for 30 days so you can review your history, then deleted. Set retention to zero on your account and we keep only timestamp, token count and cost, which is the minimum billing requires.

Staff cannot read your runs

Support has no routine access to run contents. If you ask us to investigate a specific run, you grant access explicitly, that grant is time-limited, and it is written to an audit log you can request.

Encrypted throughout

TLS 1.3 in transit with HSTS. AES-256 at rest. Tokens are stored hashed, so a database compromise does not yield usable credentials.

Tokens are scoped and revocable

API tokens are shown once and stored hashed. Revoking a token takes effect immediately and does not interrupt runs already in flight.

Isolation between accounts

Every query in the application is scoped by account at the data layer, not by a filter in the UI. There is no code path that reads another account's runs.

Compliance, honestly

We would rather write this down than let a badge imply something untrue:

FrameworkStatus
GDPRDPA available on request
SOC 2 Type IIObservation period in progress
ISO 27001Gap assessment complete
HIPAANot supported
PCI DSSNot supported
FedRAMPNot supported

Do not send protected health information or cardholder data through these agents. If your workload requires HIPAA or PCI controls, we are not the right provider today and we will tell you that rather than take the business.

Where processing happens

Account data is stored in the EU. Run processing happens in the EU and the US depending on the agent and current capacity. Enterprise accounts can pin processing to a single region; ask and we will confirm in writing which agents are available under that constraint.

Subprocessors

We use model providers to execute agent reasoning, a cloud host for infrastructure, Stripe for payments and an email provider for transactional mail. The current list with locations is available on request and we give 30 days' notice before adding one.

What you should still do

Redact what the agent does not need. If Document Extractor only needs the invoice total and date, there is no reason to send it the bank details on the same page. The cheapest security control is not transmitting the data in the first place.

Reporting a vulnerability

Write to support@stijnai.shop with "security" in the subject. We acknowledge within one business day and aim to give a fix or mitigation timeline within five. There is no paid bounty, and we will not pursue good-faith research that stays inside your own account.