CENSATIMTrust & Security
Last updated: 27 July 2026
Censatim is built for professionals handling commercially sensitive information about assets and companies. This page sets out, plainly, how the service protects your data. For how personal data is handled, see the Privacy Policy.
Data residency
Core infrastructure is EU-based: our database and authentication (Supabase) run in the EU, our rate-limiting store (Upstash) in Frankfurt, and our hosting functions in an EU region. AI processing is performed via the Anthropic API (US), safeguarded by standard contractual clauses; inputs and outputs are not used to train AI models. Censatim’s own EU Taxonomy criteria database and assessment engine control what the models are asked and how findings are graded. The sub-processor list in our Privacy Policy is the complete and authoritative record of who processes data for us.
Encryption and access
- All traffic is encrypted in transit (TLS); HTTPS is enforced site-wide with HSTS.
- Data is encrypted at rest by our infrastructure providers.
- Database credentials with elevated privileges are held server-side only and never exposed to the browser.
- Sign-in is passwordless (secure emailed link), so no passwords are stored to be lost.
Application security
- Security headers enforced site-wide: HSTS, X-Frame-Options (clickjacking protection), content-type sniffing protection, referrer policy, and a restrictive permissions policy.
- Per-IP rate limiting on all assessment and upload endpoints to prevent abuse.
- Uploaded files are size-limited, processed transiently for fact extraction, and the raw files are not retained with the assessment record.
Your documents
Documents you upload are read once to extract the facts relevant to your assessment; the concise extract is what the assessment uses and what is retained. Treat the extract as part of your assessment record: it is visible to you in-session and included in the internal assessment record that supports the service.
Deletion
You can request deletion of your assessment records and account data at any time via support@censatim.com. Deletion requests are honoured as soon as possible and always within one month.
Responsible disclosure
If you believe you have found a security vulnerability, please report it to support@censatim.com. We ask that you do not access data that is not yours, and we commit to investigating promptly and not pursuing good-faith researchers.
What we do not do
- No tracking cookies and no advertising trackers; analytics are cookieless and aggregate.
- No training of AI models on your inputs or outputs.
- No sale of your data, ever.
Enterprise clients: a Data Processing Agreement and security questionnaire responses are available on request via consult@censatim.com.