Security and data handling

Last updated 1 October 2026. This page describes what Citelode does today. We don't hold SOC 2 or ISO 27001 certification, and we won't imply that we do.

Where your documents are processed

Parsing (XLSX, DOCX, PDF, CSV, text), question detection, matching, answer drafting and building the completed file all run in your browser, using the same open code our tests run. The server never executes or parses your uploaded files.

The free tools (complexity analyser, readiness check, demo) send nothing about your files to us. They only count anonymous page events.

No third-party AI models

Citelode doesn't send your documents or questionnaires to any language-model provider. Answers are extracted from your own approved answers and documents by deterministic code. Nobody uses your data to train AI models: not us, and no one else through us.

What is stored, and how

Access control

Retention and deletion

Subprocessors

Reporting a vulnerability

Email gerber.renier1@gmail.com with the subject "Security". Please don't access other people's data while testing.

Future options

The processing engine is a self-contained JavaScript module, so a fully local or self-hosted mode is possible. Ask us if you need it.