Trust

Your RFQs are commercial secrets. The storage policy is deliberately aggressive.

An RFQ package contains what a part costs to make and who is asking for it. This page describes exactly what happens to those bytes.

What happens to an upload

  1. It is stored privately, under a random job id

    Never under a guessable name, never in a public bucket, never behind a URL the client can see.

  2. It is parsed and read once

    Text, tables and image content are extracted so the fields can be checked.

  3. The bytes are deleted — success or failure

    Deletion happens as soon as extraction finishes, including when the request is interrupted. This is not a scheduled cleanup job that might be skipped; it is on the same code path as the report.

  4. Only the report remains

    The extracted findings, kept under its own key with an expiry date.

The report

Who can open itAnyone with the report link. It is unguessable, not password-protected — treat it as you would treat any unguessable link.
How long it lives30 days by default, then it is gone. You can delete it yourself from the report page at any time.
What is in itExtracted field values and the quoted line of source each one came from. Not the original files.

Document content is treated as untrusted input

A customer can put any text in an RFQ, including text shaped like instructions. Document content is delimited as data inside the prompt and can never change what the tool is asked to extract, and every extracted value is re-verified against the source file before it can appear in a report. A value that cannot be traced to a literal quote in a real segment is dropped, and the report shows a dash instead.

Error logs record the shape of a failure. Document content is never written to a log.

How the site itself is built

  • Every page is served with Content-Security-Policy: default-src 'none', so no third-party script, font, image or analytics request is possible. There is no tracking pixel on this site because there is nothing to run one.
  • X-Frame-Options: DENY and frame-ancestors 'none' — this site cannot be framed.
  • X-Content-Type-Options: nosniff and a strict referrer policy on every response.

Questions about a specific package? Get in touch.