Security and data handling
Last updated 1 October 2026. This page describes what Citelode does today. We don't hold SOC 2 or ISO 27001 certification, and we won't imply that we do.
Where your documents are processed
Parsing (XLSX, DOCX, PDF, CSV, text), question detection, matching, answer drafting and building the completed file all run in your browser, using the same open code our tests run. The server never executes or parses your uploaded files.
The free tools (complexity analyser, readiness check, demo) send nothing about your files to us. They only count anonymous page events.
No third-party AI models
Citelode doesn't send your documents or questionnaires to any language-model provider. Answers are extracted from your own approved answers and documents by deterministic code. Nobody uses your data to train AI models: not us, and no one else through us.
What is stored, and how
- Stored: the text extracted from documents you add, your Gold Answers and security profile, each questionnaire's questions and drafted/approved answers, the original questionnaire file (needed to produce the completed copy) and the exports you create.
- Encryption at rest: content is encrypted with AES-256-GCM using a key derived (HKDF-SHA-256) separately for each workspace. Each encrypted record is bound to its own record ID, so ciphertext can't be moved between records or workspaces. Storage is Cloudflare D1, which is also encrypted at rest by Cloudflare.
- In transit: HTTPS only (HSTS).
- Original files are never modified. Exports are written into a copy, and the original's SHA-256 hash is recorded.
Access control
- Every query is scoped to your workspace. A request for another workspace's records returns "not found" and is written to the access log. Our automated tests include cross-workspace access attempts.
- Sessions use HttpOnly, SameSite cookies. Every change needs a per-session CSRF token and a same-origin check. Passwords are hashed with PBKDF2-SHA-256 (100,000 iterations). Sign-in and sign-up are rate-limited.
- Exports are downloaded through signed links that expire after 10 minutes and also require your session.
- Your workspace's access log (sign-ins, uploads, reads, exports, approvals, refused access) is visible under Settings.
Retention and deletion
- Questionnaires, their answers and exports are deleted automatically after a period without activity: 90 days by default, adjustable from 7 to 730.
- Documents and Gold Answers stay until you delete them, because they are your reusable knowledge base.
- Settings → Delete workspace permanently removes everything, including your login.
Subprocessors
- Cloudflare, Inc.: hosting, database and network (global edge; data at rest in Cloudflare D1).
- Polar Software Inc.: payments, as merchant of record. Polar receives your email and payment details, never your documents.
- cdnjs (Cloudflare): serves the open-source PDF reader library your browser loads. It receives no document content.
Reporting a vulnerability
Email gerber.renier1@gmail.com with the subject "Security". Please don't access other people's data while testing.
Future options
The processing engine is a self-contained JavaScript module, so a fully local or self-hosted mode is possible. Ask us if you need it.