Security & Privacy
Your business data is sensitive. We treat it that way. Here's exactly how Software Multitool protects your files, results, and organization data.
Encryption Everywhere
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Your files and results are never transmitted or stored unencrypted.
Files Deleted After Processing
Uploaded files are processed to generate your results and immediately deleted. We do not retain your documents after your job completes.
No Training on Your Data
Your files and outputs are never used to train AI models — ours or any third party's. Your proprietary information stays yours.
Tenant Isolation
Every organization's data is logically isolated. Your files, jobs, and results are never accessible to other users or organizations.
Secure Authentication
Support for password auth, magic links, OAuth (Google, GitHub), two-factor authentication, and passkeys — with session management and automatic expiry.
Audit Logs
Every significant action in your organization is logged. Admins can review audit logs at any time to track access, changes, and exports.
Trusted Infrastructure
Hosted on Vercel and Supabase — enterprise-grade cloud providers with SOC 2 Type II certifications, 99.9% uptime SLAs, and global CDN delivery.
Role-Based Access Control
Organization admins control who can access which tools and data. Invite team members with defined roles — owner, admin, or member.
Built on enterprise-grade infrastructure
Security FAQ
Who can see my uploaded files?
Only you (and your organization members if you share access). Files are processed in isolated containers and deleted immediately after the job completes.
Are my files used to train AI?
No. Your files are never used to train or fine-tune any AI model. Your data is used only to generate your requested output.
Where is my data stored?
Data is stored in secure cloud infrastructure (Supabase / AWS), encrypted at rest and in transit. You can request deletion of your account and all associated data at any time.
How long are files kept?
Uploaded files are deleted after processing completes — typically within seconds to a few minutes. Output results are stored in your account for as long as your account is active.
Do you have a data processing agreement (DPA)?
Yes. Contact us to request a DPA for your organization if required for compliance purposes.
What happens to my data if I close my account?
All your data — files, job results, and personal information — is deleted within 30 days of account closure.
Questions about security or compliance?
We're happy to provide a data processing agreement, answer specific compliance questions, or discuss your organization's requirements.