Where your files actually go.
Last updated 13 August 2026 · KRAYON-AI, LLC
Most vendors answer this question with a logo wall and the word "enterprise." The honest version is shorter and more useful: your documents are read by machines we own, sitting in Florida, that do not have permission to send your file contents anywhere. Everything below is the detail behind that sentence, including the parts that are limitations rather than features.
1. Hardware we own and operate
Document processing runs on computers that KRAYON-AI, LLC owns outright and physically controls in Florida. They are not rented instances, not a colocated tenancy, and not someone else's cloud with our name on the invoice. Nobody can reassign, image, or subpoena the underlying host out from under us, because there is no underlying host — there is a machine, and we own it.
This is the entire architectural reason the service exists. A firm that cannot let privileged records leave its control cannot use a tool whose vendor cannot say where the records went.
2. No public AI services in the document pipeline
The language models that read your documents run locally on the hardware described above. Your file contents are not transmitted to OpenAI, Anthropic, Google, Microsoft, Amazon, or any other third-party model service at any point in the document workflow. There is no fallback path that quietly ships an over-long document to a commercial API when a local model struggles — if a job is too large for the hardware, it takes longer, it does not leave the building.
3. Per-client isolation
Privileged document work is separated per client. In practice that means three things:
- No shared working directory. Each matter is processed in its own isolated workspace. One client's files are never enumerable from another client's job.
- Dedicated hardware on request. For firms that require it, we assign a specific machine to that firm. Their files never share a disk with another client's files. This is the default posture for engagements involving protected health information, and it is available to any client who asks.
- No cross-client indexing. We do not build a combined search index, a shared knowledge base, or any other structure that spans clients. There is nothing to leak across, because nothing spans.
4. Encryption
In transit. Files move over encrypted connections. We will also accept and return files through your own secure portal or file-transfer system, so the chain of custody stays inside tooling your firm has already approved.
At rest. Processing runs on Apple silicon hardware, where the storage is hardware-encrypted at rest by the platform's secure enclave at all times. Any machine assigned to a client engagement additionally has full-disk encryption enabled, so that its data volume cannot be read without authentication — a machine that is lost, stolen, or seized does not become a disclosure. If your engagement requires it, we will confirm the encryption status of the specific machine assigned to you in writing before any file is transferred.
Disposal. Storage media are cryptographically erased or physically destroyed before disposal or resale. Hardware does not leave our control carrying recoverable client data.
5. Access control and logging
Access to client documents is limited to the individuals who need it to complete your work. Machines used for document processing require authentication, and administrative access is restricted to the principal of the company.
Access to your files is logged for the life of your matter — who, what file, when — and that log is delivered to you with the work product rather than kept as something you have to ask for. Logs are retained for twelve months, longer than the files themselves, because a log that expires with the data it describes cannot answer the question you would actually be asking.
To be exact about what that is: this is a per-engagement record maintained by a small firm, not an enterprise audit platform with a compliance dashboard. It is a document you can read, hand to a partner, and put in a file. If your requirements call for tamper-evident or independently attested logging, say so before you engage us — we will tell you plainly whether we can meet it rather than discovering the gap during your security review.
6. Deletion, enforced on a schedule
Published and enforced, not aspirational. Periods run from delivery of your work product:
Backups containing client documents rotate on a cycle no longer than the retention period for the data they hold, so deleting a file does not leave a copy alive in a backup image for a year. Longer retention — a file held for the life of a matter — is available as a written agreement rather than a default.
7. People
The smallest attack surface in this company is the org chart. Client documents are handled by the principal and, where a licensed reviewer is used for medical work product, by a contracted reviewer bound by a written confidentiality agreement. There is no offshore processing team, no contractor marketplace, and no support tier with standing access to your files.
Work product is reviewed by a person before delivery. We do not ship unreviewed model output as a finished document.
8. Website and application security
This website is static and served through a hardened content delivery network with automated abuse protection and rate limiting on every interactive endpoint. It carries no third-party advertising or analytics scripts, which removes an entire category of supply-chain risk. Payment webhooks are cryptographically signature-verified and replay-protected.
The website is not the document pipeline. Nothing you submit through a form on this site travels to the machines that process documents, and no client document is ever stored on or served from this website.
9. Incident response
If we detect or are notified of a security incident affecting client data, we contain it first, then determine scope, then notify. Affected clients are notified without unreasonable delay and within any period required by law or by our agreement with you. Where a Business Associate Agreement is in place, we meet the reporting obligations in that agreement.
We will tell you what we know when we know it, including when the answer is "we are still determining scope." You will not learn about it from someone else first.
10. What we are not
A security page that only lists strengths is a sales document. Here is the other half, so you can make a real decision:
- We are not SOC 2 certified. We are a small Florida company, not an enterprise vendor with an audit budget. If your procurement process requires a SOC 2 Type II report as a hard gate, we will not pass it today, and we would rather you know that now than after four calls.
- We are not a 24/7 operation. Turnaround for document work is typically overnight, but there is no follow-the-sun support desk. Emergencies reach a human by phone.
- We do not offer a customer-managed encryption key model, a private VPC deployment, or a self-hosted appliance today. Dedicated hardware under our control is the isolation model we offer.
- Text messages travel over carrier networks. For messaging products, message content necessarily passes through telecommunications providers. No vendor can honestly claim otherwise.
What we do offer against those gaps is specificity: named hardware, a written deletion schedule with a deadline, an access log you can actually read, and a principal who answers the phone.
11. Security review and questionnaires
Send your security questionnaire, outside-counsel guidelines, or IT policy and we will complete it. If something in your requirements is a genuine dealbreaker for a company this size, you will be told on the first pass rather than in month three.
Requests: king@krayon-ai.com · 813-733-5997
Read alongside our privacy policy and terms of service. Where a signed agreement between us differs from this page, the signed agreement governs.