Trust

Security at OSQR

One page, everything a security review asks for — including the parts most companies bury. If your team has a questionnaire, we will complete it: info@osqr.ai.

01The honest model, up front

OSQR is an AI that reads your documents and conversations in order to work for you. That means it is not "zero-knowledge" and we will never pretend otherwise: our servers decrypt your content to answer your requests, then drop it from working memory. The real security questions are the ones we answer below — who can access what, what leaves our systems, what is retained, and what happens when something goes wrong.

02Encryption

  • At rest: user content (documents, messages, summaries) is encrypted with AES-256-GCM using per-account data keys, on top of infrastructure-level disk encryption. A raw database leak yields ciphertext, not your documents.
  • In transit: TLS 1.2 or higher (TLS 1.3 on modern clients) everywhere.
  • Credentials: passwords are hashed, never stored; OAuth tokens are encrypted at rest.

03Who can access your data

  • You, and the people you explicitly add to your workspace. Data is isolated per account.
  • OSQR staff do not browse user content in normal operation. Any access is purpose-bound, restricted, and logged. For child accounts, every access by anyone at OSQR is written to a parent-visible, hash-chained log before a word is read.
  • AI model providers (Anthropic, OpenAI, Google, xAI, Groq) receive only the text a request needs, under agreements that prohibit training on it. Full list, with data types and locations: subprocessors.
  • No training, no selling, no ads. OSQR does not train AI models on your data, does not sell it, and does not build advertising profiles from it.

04Business documents and bid data

For contractors using OSQR on plans, takeoffs, and bids: your plan sets and estimates are workspace-isolated and are never used to train models or shared across customers. Where our estimating service includes human-in-the-loop processing, that access is part of the service and disclosed — not hidden. If you license specific documents to us in writing (for example, historical takeoffs used to grade accuracy against your own numbers), that written license governs exactly what we may do, and it never includes model training.

05Infrastructure

  • Hosting: Vercel (US) · Database: Neon PostgreSQL (AWS) · Files: AWS S3 — all US-based.
  • Payments: Stripe. OSQR does not store card data.
  • Data residency is US-only today; EU residency is on the roadmap.

06Retention and deletion

  • Your data is retained until you delete it. Deleted accounts are purged within 30 days; encrypted backups within 90 days.
  • Retention is enforced by automated jobs, not by hand: audit logs pruned at one year, IP addresses redacted at 90 days, model cost logs at 90 days.
  • "Burn It" deletes everything permanently in one action — keys destroyed, content purged, no cold-storage copy.

07If something goes wrong

  • We will notify affected customers within 72 hours of discovering a breach affecting personal data — the same commitment published in our Terms, DPA, and transparency report.
  • Found a vulnerability? Tell us: info@osqr.ai (see /.well-known/security.txt). We take coordinated disclosure seriously and will respond within 24 hours.

08What we do not have yet — said plainly

  • No SOC 2 certification yet. A readiness program is underway (compliance platform, then a Type II observation period), with an independent penetration test planned for 2026. Our 15-policy internal control set is available for review on request.
  • Not HIPAA compliant — do not upload PHI.
  • No native MFA yet — Google sign-in carries Google's MFA; recovery codes protect encrypted-data access; TOTP is on the roadmap.
  • We would rather tell you this on page one than have your security team find it on page ten. A small company earns trust with honesty and architecture, not with logos it does not have.