Skip to content

Security

Where your content goes, in plain language

You send us documents to fact-check, so you deserve a precise answer to who sees them, where they are stored, and for how long. This page describes what we do today, not what we plan to do.

The data flow

  1. From your browser to our app. Everything travels over TLS. Document uploads go directly to private cloud storage through short-lived signed URLs.
  2. From our app through OpenRouter to the model providers. To check a document, we send the relevant text to a panel of AI models through the OpenRouter gateway, which routes it to the model providers on your panel (for example Anthropic, OpenAI, or Google). We route these calls with OpenRouter's data-collection opt-out, which excludes hosts that would retain or train on prompts.
  3. Live research. On live-research checks, we also send claim text to web-search providers so the models can verify it against current sources.
  4. Quality verification. Alongside the panel, an automated verification service (TypeSafe AI) checks the pipeline's own work: that each extracted claim matches your document, that gathered evidence is on topic and free of instructions aimed at the models, and that cited sources support the verdict. It receives the document text, the claim text, and that evidence. This provider is outside the OpenRouter gateway, so the gateway's opt-out does not apply to it. Instead, a data-processing agreement bars it from training on your content or using it for anything else. It is not a zero-retention service. It keeps data only as long as it needs to provide the service.
  5. Results in your account. We store votes, verdicts, and reports in our database. Only your organization can see them. A report becomes publicly reachable only if you share it.

Encryption

  • In transit. TLS for traffic between your browser and us, and between us and every provider listed below.
  • At rest. Our databases and document storage are encrypted at rest with keys the cloud provider manages. We also encrypt connector API keys you supply at the application level before storing them.
  • Network isolation. The processing pipeline and databases run inside a private network with no exposure to the internet.

Retention

We keep your documents and fact-check reports until you delete them or your account. They exist so you can revisit your reports, and for no other purpose. Account data lives as long as your account does. Billing records live as long as tax law requires. Server and API logs are deleted automatically after a limited period. We do not sell your data or use your documents to train AI models. The Privacy Policy describes deletion and export requests.

Subprocessors

These are the providers that touch service data, each engaged under terms that restrict use to providing their service to us:

ProviderPurposeData involved
Amazon Web ServicesHosting, document storage, databases, background processingAll service data (US region)
WorkOSAuthentication and organization managementName, email, organization membership
StripePayment processingBilling details; we never see or store card numbers
OpenRouterAI gateway routing claims to model providersClaim/document text sent for checking
AI model providers (Anthropic, OpenAI, Google, DeepSeek, and others on your panel)Running the fact-check analysisClaim/document text, via OpenRouter
Web-search providers (model-native search; Tavily, Exa)Live web research on Tier-3 checksClaim text being researched
TypeSafe AIAutomated quality verification of claims, evidence, and citationsDocument/claim text and the evidence gathered for a check (US-hosted)
Plausible AnalyticsAnonymized, cookieless website analyticsAggregate page statistics only (EU-hosted)

For EU customers

Fact Engineering Inc., a US (Delaware) company, operates Fact Engineering. The service is hosted and processed in the United States. That includes AI inference: US-based model providers process the text you submit for checking. Where we transfer personal data of EU/EEA, UK, or Swiss residents, we rely on safeguards such as Standard Contractual Clauses and providers' EU-US Data Privacy Framework certifications. The Privacy Policy has the details.

If you need more information

If your security or vendor review needs more than this page, such as questionnaires, infrastructure specifics, or contractual terms, email support@fact.engineering and we will answer directly. See also our Terms of Service and Privacy Policy.