Security & data handling

Your documents are encrypted, deleted on a clock, and never used for training.

For institutional buyers: this page is the short version of what we’d send in a security review. Long version, including DPA template and subprocessor list, is downloadable below.

Encryption

AES-256 at rest. TLS 1.3 in transit. Database row-level encryption for document text.

Retention

Documents deleted 30 days after last edit (user-configurable). Backups purged within 35 days.

Training

User documents are never used to train any model. Our adapter is trained on public + author-permissioned data only.

Access controls

Row-level security in the database. No human at Rewritelyapp can read your documents without an explicit support consent flow.

Hosting

Google Cloud Run (europe-west1) for the app layer. Supabase (EU) for data. Vertex AI (europe-west4) for the model.

Monitoring

Cloud-native logging with PII scrubbing. Anomaly alerts on unusual access patterns. Public status page.

Compliance & certifications

StandardStatusNotes
GDPRCompliantEU-hosted, DPA on request, data-subject rights via app or email.
UK GDPR / DPA 2018CompliantUK registered, ICO registered.
CCPA / CPRACompliantRight to know, delete, opt-out honoured.
SOC 2 Type IIn progressTargeting Q4 2026 audit.
ISO 27001Planned 2027Subject to demand from institutional buyers.
FERPA-awareYesWe treat all student documents under FERPA-aware handling even when not technically subject to it.

For institutional buyers

If you’re evaluating Rewritelyapp for a writing center, a research lab, or a department-level rollout, we have the following ready:

  • Data Processing Agreement (DPA), pre-signed by us, ready to countersign.
  • Subprocessor list, the full set of vendors that touch user data.
  • Security questionnaire, we’ve answered the CAIQ-Lite and a custom UK-HE security questionnaire; both available on request.
  • SSO setup, SAML 2.0 with Google Workspace, Microsoft Entra, and Okta tested in production.
  • Single-region data residency, EU by default; US region available for US institutions on request.
  • Disclosure for academic-integrity teams, we publish what Rewritelyapp will and won’t do at academic-integrity.html.

Request the security pack