Fort Knox, not a hotel safe.
Verifiable and Transparent Due Diligence
Here's how a file moves through the system:
Your file
↓TLS 1.2+ encrypted
Google Cloud Organization Perimeter
SOC 2 Type II · ISO 27001 · VPC Service Controls
Private VPC
No public IP address
App server
Cloud Run
Masking engine
Sealed
Private storage
Cloud SQL + GCS
↓
Deletion Audit Log
Independent of application code
↓TLS 1.2+ encrypted
Masked file
Destroyed after delivery — logged independently
Control Boundaries
What each boundary does
| Control | Mechanism | Verification |
|---|---|---|
| Data cannot leave the environment | VPC Service Controls, org-level perimeter | Enforced at platform level, not application config |
| No public network exposure | No public IP on database or storage | No route from the open internet |
| No LLM in the pipeline | Google Cloud DLP + deterministic algorithms only | No LLM ever processes values |
| Deletion is enforced | GCS Lifecycle Management rule, 48-hour max | Every deletion independently logged |
| Infrastructure is independently audited | Google Cloud, SOC 2 Type II, ISO 27001 | Platform-level certification |
The bottom line
Files are encrypted, hidden, protected, processed, and deleted. No unauthorized access, either direction.
Detection accuracy is tested and published, including known limits — see /accuracy.