SECURITY & DATA PROTOCOL
Legally Protected. Cryptographically Secure.
Private market diligence demands that a vendor be precise about what it holds and for how long. This page separates what we have implemented from what we have merely written down, because that is the distinction your risk officer is actually testing for. Your documents are never used to train a model, and they do not outlive the window stated below.
// THE ARCHITECTURE
The Enterprise Security Architecture
Layer 01 — Bounded Ingestion
The Reality: Standard conversational tools utilize your unique inputs, deal metadata, and internal queries to train public neural networks. You are quietly leaking your fund's proprietary operational alpha to the public cloud with every prompt.
The askOdin Standard: Your data rooms, financial models, and strategic notes are processed in isolated execution environments and held no longer than 30 days under a documented retention ceiling. What survives that window is derived — the verdict, the judgment analysis, and structural data — never the documents themselves. That structural record can include identifying details, so it stays subject to erasure. As a matter of policy, we do not read your documents.
Layer 02 — Tenancy, Stated Plainly
The Reality: Shared processing tiers expose sensitive transaction pipelines to cross-tenant leakage. This is a hard problem, and we will not pretend we have finished solving it when we have not.
The askOdin Standard: askOdin runs shared, and isolation of the processing cache is being hardened — that work is not complete. Single-tenant deployment, configurable processing region and deployment inside your own perimeter are on the roadmap and are not shipped. If any of those gate your firm, the honest answer today is that we are not ready for you, and we would rather tell you now than at the evidence request.
Layer 03 — Cryptographic Trail Generation
The Reality: A conversational chatbot history that outputs a slightly different response based on how a prompt is worded cannot survive a rigorous fiduciary audit.
The askOdin Standard: The verdict is computed outside the language model by a deterministic engine, so the compiled graph is invariant: bind the same variables and the same score comes back every time. Extraction is not frozen forever — it runs on an external model, and model versions move. That is why every audit is anchored to a SHA-256 of the exact files, and why a past result is verified by reading its record rather than by re-running it.
// THE SECURITY PROTOCOL
Built for the Risk Officer.
No Training Use
Your documents do not train anything — ours or anyone else's.
Extraction runs on the Google Gemini Developer API under a paid-tier agreement that prohibits training use, behind a swappable adapter. No customer document enters any training corpus, and askOdin does not fine-tune or distil a model on customer material. That is contractual and architectural, not aspirational.
Stateless API Orchestration
Execution is isolated per request.
The language layer reads and extracts only. It never evaluates, and it carries nothing between requests. Every calculation and every verdict is produced by a statically-typed Go engine running against the extracted variables — the separation is what makes the audit trail mean anything.
Bounded Retention
Raw documents are held no longer than 30 days.
That ceiling is a documented policy. Automated enforcement of it is In Progress and ships with SOC 2 Type I — until then deletion is executed on request, and we would rather say so than call it a control. What persists past the window is derived: the verdict, the judgment analysis, and structural data. Never the documents. That structural record can include identifying details, so erasure rights reach it.
Cryptographic Anchoring
Every audit is bound to the exact files it read.
Submitted documents are fingerprinted with SHA-256 and the result is anchored to those hashes. That is what lets a third party confirm the deck they were sent is the deck that was scored, rather than a later revision wearing an older result. A fingerprint fails loudly when the file changes.
Edge & Transport
Inherited from Cloudflare, not asserted by us.
- Edge & storage: Cloudflare WAF, DDoS protection, CDN, R2 object storage
- At rest: AES-256, as provided by R2
- In transit: TLS 1.3
- API access: token-based auth with scoped permissions
Jurisdiction
Singapore — a recognised financial centre under English Common Law.
- Legal framework: Singapore Companies Act, PDPA compliance
- IP protection: four U.S. provisional patents filed
- Sub-processors: full list provided under NDA
Compliance Roadmap
A stated policy is not an implemented control, and an implemented control is not an evidenced one. Vendors who blur those three get caught at the evidence request. Here is which column each of ours sits in.
- AES-256 / TLS 1.3 encryption
- Cloudflare WAF + DDoS protection
- Documented 30-day retention ceiling
- PDPA (Singapore) compliance
- SOC 2 Type I certification
- Automated retention enforcement
- GDPR Data Processing Agreement
- Penetration testing (third-party)
- SOC 2 Type II certification
- ISO 27001
- Single-tenant deployment
- Configurable processing region
- On-premise deployment option
// OBJECTION HANDLING
Security & Compliance FAQ
How our data is handled
Does askOdin train its models on the data we upload?
No. Extraction runs against an external model API under a paid-tier agreement that prohibits training use; the deterministic engine does the analysis. Raw documents are held no longer than 30 days under a documented retention ceiling. What persists beyond that is derived — the verdict, the judgment analysis, and structural data in the Judgment Graph benchmark corpus. That structural record can include identifying details such as founder names, so it remains subject to your erasure rights; systematic de-identification is on the roadmap, not shipped. No customer document enters any training corpus.
Where is our data processed — what data-residency options exist?
Processing region is configurable per deployment; the default jurisdiction is Singapore under PDPA, with EU and US residency available for dedicated instances.
Who are askOdin’s sub-processors?
Cloudflare for edge security and object storage, and the Google Gemini Developer API for document extraction, behind a swappable adapter layer. Extraction is the model's only role — it maps unstructured documents into typed variables, and the deterministic engine does the analysis. The full sub-processor list is provided under NDA.
Contracts and certification
Is askOdin SOC 2 or ISO 27001 certified?
Not yet. Implemented controls: AES-256 at rest, TLS 1.3 in transit, stateless API orchestration, a documented 30-day retention ceiling on raw documents, and PDPA compliance. In progress: SOC 2 Type I, a GDPR Data Processing Agreement, and automated enforcement of the retention policy. On the roadmap: SOC 2 Type II and ISO 27001. We distinguish a stated policy from an implemented control and will tell you which is which — documentation is available under NDA for your security review.
Will askOdin sign a DPA, and do you use Standard Contractual Clauses?
A Data Processing Agreement with Standard Contractual Clauses for cross-border transfers is in preparation and is not yet available for signature. Contact the security team and we will tell you where it stands rather than quote a date we cannot evidence.
Deployment and audit trail
Can askOdin run as a stateless or dedicated instance?
Yes. Institutional deployments run as dedicated instances under strict data sovereignty, and raw documents are held no longer than 30 days; the derived judgment record persists so the audit trail survives the document. Tenant isolation on the shared processing cache is being hardened and is not yet complete — if strict isolation is a gating requirement for your firm, talk to us before you upload anything, and we will tell you exactly where that work stands.
Is the output auditable and defensible to a regulator?
Yes. askOdin is a deterministic compiler, not a probabilistic black box. Every verdict produces a Defensible Audit Log with cross-document provenance — reconstructible under fiduciary inquiry or regulatory examination.
Questions about security?
We welcome security reviews and provide detailed technical documentation for your compliance team.