Customer data is not foundation-model training data.
Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.
Security · Privacy · Trust
Esheria documents identity, encryption, access, audit, token, privacy, model-processing, incident, and deployment controls without publishing certification claims that cannot be substantiated with scope and validity details.
Core commitments
Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.
API and OAuth tokens are never placed in marketing URLs, analytics payloads, public repositories, or generated discovery artifacts.
Tokens, OAuth grants, pack entitlements, feature entitlements, scopes, and rate limits remain server enforced.
Data is protected in transit and at rest with access controls appropriate to the deployed product and agreement.
Trace IDs, token metadata, usage events, deployment evidence, and operational logs support investigation without exposing token secrets.
Current security, privacy, sub-processor, residency, and contractual materials are supplied through the trust-review process.
Certification language
Any public certification claim must identify its status, issuer, certificate identifier, certified scope, and validity period.
Until those details are approved for publication, Esheria describes implemented controls and provides substantiating trust materials during procurement rather than making an unqualified certification claim.
Trust documents
How Esheria handles account, website, product, support, and customer-controlled personal data.
OpenProcessor terms, instructions, safeguards, sub-processors, transfers, and deletion obligations.
OpenDeveloper use, licensing boundaries, credentials, acceptable use, fees, and legal-information disclaimers.
OpenRequest current trust, procurement, security, privacy, and support material.
Open