Security
Where your content goes, in plain language
You send us documents to fact-check, so you deserve a precise answer to “who sees them, where do they live, and for how long.” This page describes what we actually do today — no aspirational language.
The data flow
- Your browser → our app. Everything travels over TLS. Document uploads go directly to private cloud storage via short-lived signed URLs.
- Our app → OpenRouter → model providers. To check a document, we send the relevant text to a panel of AI models through the OpenRouter gateway, which routes it to the model providers on your panel (e.g. Anthropic, OpenAI, Google). We route these calls with OpenRouter's data-collection opt-out, which excludes hosts that would retain or train on prompts.
- Live research. On live-research checks, claim text is additionally sent to web-search providers so models can verify against current sources.
- Results → your account. Votes, verdicts, and reports are stored in our database and visible only to your organization — a report becomes publicly reachable only if you explicitly share it.
Encryption
- In transit: TLS for traffic between your browser and us, and between us and every provider listed below.
- At rest: our databases and document storage are encrypted at rest with cloud-provider managed keys. Connector API keys you supply are additionally encrypted at the application level before storage.
- Network isolation: the processing pipeline and databases run inside a private network, not exposed to the internet.
Retention
Your documents and fact-check reports are kept until you delete them or your account — they exist so you can revisit your reports, not for any other purpose. Account data lives as long as your account does; billing records as long as tax law requires; server and API logs for a limited period before automatic deletion. We do not sell your data or use your documents to train AI models. Deletion and export requests are described in the Privacy Policy.
Subprocessors
These are the providers that touch service data, each engaged under terms that restrict use to providing their service to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Hosting, document storage, databases, background processing | All service data (US region) |
| WorkOS | Authentication and organization management | Name, email, organization membership |
| Stripe | Payment processing | Billing details; we never see or store card numbers |
| OpenRouter | AI gateway routing claims to model providers | Claim/document text sent for checking |
| AI model providers (Anthropic, OpenAI, Google, DeepSeek, and others on your panel) | Running the fact-check analysis | Claim/document text, via OpenRouter |
| Web-search providers (model-native search; Tavily, Exa) | Live web research on Tier-3 checks | Claim text being researched |
| Plausible Analytics | Anonymized, cookieless website analytics | Aggregate page statistics only (EU-hosted) |
For EU customers
Fact Engineering is operated by Fact Engineering Inc., a US (Delaware) company, and the service is hosted and processed in the United States — including AI inference: the text you submit for checking is processed by US-based model providers. Where we transfer personal data of EU/EEA, UK, or Swiss residents, we rely on safeguards such as Standard Contractual Clauses and providers' EU–US Data Privacy Framework certifications. Details are in the Privacy Policy.
If you need more information
If your security or vendor review needs more detail than this page — questionnaires, specifics about our infrastructure, or contractual terms — email support@fact.engineering and we'll answer directly. See also our Terms of Service and Privacy Policy.