Security and data handling
Documents carry the most sensitive material a business holds, and a document system is therefore a data-protection decision before it is a productivity one.
Every request is checked against the role that made it
Access is enforced per request, at the boundary, against the identity making it — not decided once at login and trusted thereafter, and not enforced only in the interface. A capability the interface does not offer you is a capability the server also refuses.
Roles separate what a person may do from what they decided. Those are deliberately different records: widening who may act should never quietly rewrite the history of who acted.
Records age out
Document data is retained on a fixed window and swept when it expires, rather than accumulating by default. Retention that depends on somebody remembering to delete things is not retention policy, it is an intention.
Traceability is a security property
Because every value resolves to a file, page and span, an incident question — what did this system actually hold about this person — has a concrete answer rather than an estimate. The same mechanism that makes an extraction checkable makes a disclosure request answerable.
Where documents are processed
Reading a document involves model inference, and inference runs on named infrastructure. The current list of processors and the regions they run in is available on request: privacy@sheaf.us.
Data-processing terms, including the standard agreement and any regional addenda, are handled through privacy@sheaf.us, which will return the current data processing agreement for signature.
Current posture
- SOC 2 Pending. Status and expected date on request.
- ISO 27001 On the roadmap, not certified.
- HIPAA Workflow-ready. A BAA is available on request under an enterprise agreement.
Pending is not certified and roadmap is not pending. These are written the way they are so that a security review does not have to discover it later; if a certificate is a hard requirement today, say so early and we will tell you where the work actually stands.
Reporting a vulnerability
Security reports go to security@sheaf.us and are acknowledged within 3 business days. Please include enough detail to reproduce; we will not pursue anyone acting in good faith under a reasonable disclosure timeline.
Sheaf