Skip to content
ProSearchAI

Your drawings, contracts and handbook are the company. Here is how they are kept.

A plain description of how ProSearchAI stores and protects your documents and who can see them. If your GC, IT consultant or insurer needs more detail, write to kevin@krselectric.net and we will answer their questionnaire.

How it works

Your company's rows are walled off in the database itself

Every business table carries a company id and PostgreSQL row-level security is turned on for all of them: documents, pages, chunks, embeddings, questions, answers, images, certifications, contacts. The application connects as a role that cannot bypass it and sets the active company on each request. A query for another company's document returns nothing, even if the application code had a bug. Our operator tools use a separate role, and every use of it is written to an audit row.

Files live in a private bucket and are only reached through signed URLs

Uploads go from the browser straight to Amazon S3 under your company's own prefix, through a signed URL that is good for fifteen minutes and one object. Downloads and page images work the same way. The bucket blocks all public access, is encrypted at rest with server-side encryption, and is never served directly. Deleting a document deletes its file, its page images and its index entries.

We do not train on your documents, and neither does our model provider

Text excerpts and rendered drawing pages are sent to OpenAI’s API to produce embeddings, answers, captions and transcriptions. OpenAI does not use API data to train its models, and we have its data-processing agreement in place. Nothing you upload is used to train anything, by us or by anyone we work with. Prompts are built only from your company’s documents; another customer’s documents are never in the same request.

Hosted in the United States on AWS

Production runs in AWS us-east-2 (Ohio); files are in S3 in the same account. Data does not leave the US except for the model calls above, which go to OpenAI's US endpoints. The database and the file store are not reachable from the internet; access to the servers is by key from a short allow-list of people.

Encrypted in transit and at rest

All traffic to the site, the app and the API is HTTPS with certificates issued and renewed automatically. Database volumes, backups and the file bucket are encrypted at rest with AWS-managed keys.

Passwords are hashed with Argon2id

We never store a password. Hashes use Argon2id, the current OWASP recommendation. Sessions use short-lived access tokens with rotating refresh tokens in secure, HTTP-only cookies; sign-in, sign-up and reset endpoints are rate limited.

Backed up every night

A full database dump runs nightly and is copied to a separate, versioned S3 bucket in the same region. Your files are already in S3 with versioning, so they are not dumped twice. Restores are tested as part of release.

Your data is yours: export everything, or delete everything

An owner can export the original files, the extracted text per page, the Q&A history, certifications and contacts from Settings, on every plan, with no waiting period. If you close the account we keep the data 30 days in case you change your mind, then delete it from the database and the file store; backups age out on their normal rotation.

Roles limit what each person sees

Owners, admins, managers, members and viewers each see only what their role allows. Members-only projects hide their documents and answers from everyone not on the project. Members see their own certifications and nobody else's. Changes to members, roles and settings are in the audit log.

Answers are retrieval, not judgment

The model is told to answer only from the excerpts it was given, to cite each claim, and to say when the documents do not contain the answer. Every citation opens the page it came from. Treat an answer as a fast way to find the right sheet, and read the sheet.

Straight answers

What we do not have yet.

ProSearchAI is a small company. We do not hold a SOC 2 report today; the controls above are the ones we run, and we will say so plainly rather than imply otherwise. Single sign-on and SCIM are available on Enterprise and are coming to the Company plan. Two-factor authentication for all accounts is on the roadmap. A signed DPA with our own terms is available on Enterprise; on other plans our standard terms and privacy policy apply.

Found a vulnerability? Email kevin@krselectric.net with the subject line “Security”. We respond within two business days and will credit you if you want us to.

The legal detail is in the privacy policy and terms of service.

Upload one set of drawings and ask it something.

Fourteen days, full Team features, no credit card. Drop in the plans and spec from a live job, wait a few minutes for the sheets to index, and ask the question your foreman asked you this morning.